Courseiva
Data Protection →easyMultiple Select

SCS-C02 Data Protection Practice Question

A company wants to protect data stored in Amazon S3 Glacier. The data must be encrypted at rest and the encryption keys must be rotated annually. Which TWO options meet these requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use SSE-KMS with a customer-managed key that has automatic key rotation enabled.

SSE-KMS with a customer-managed key that has automatic key rotation enabled allows annual rotation and meets the encryption requirement. Option E is correct because S3 Glacier's default encryption, SSE-S3, encrypts data at rest and AWS manages key rotation automatically on an annual basis. Option B is incorrect because AWS CloudHSM requires manual key rotation. Option C is incorrect because client-side encryption with the Amazon S3 encryption client does not use server-side encryption and requires manual key management. Option D is incorrect because SSE-C requires you to manage and rotate the keys manually.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use SSE-KMS with a customer-managed key that has automatic key rotation enabled.

    Why this is correct

    SSE-KMS with a customer-managed AWS KMS key that has automatic rotation enabled satisfies the requirement because S3 Glacier applies server-side encryption using KMS, and KMS automatically rotates the underlying key material on an annual basis without any manual action. The CMK remains the same logical key, so object references and permissions are unchanged while the encryption material is refreshed, meeting compliance policies that demand automatic key rotation. This is the most flexible option when you need separate permissions and audit trails.

  • ✗

    Use AWS CloudHSM to generate a key and encrypt data before uploading to Glacier.

    Why it's wrong here

    AWS CloudHSM provides hardware-based cryptographic key generation and client-side encryption before upload to Glacier, but it does not offer automatic key rotation. Your application must orchestrate creating new keys, re-encrypting existing objects, and deleting old keys, which is manual and error-prone. Moreover, Glacier itself cannot use CloudHSM keys for server-side encryption; you are responsible for the entire key lifecycle, so this approach fails the automatic rotation requirement.

  • ✗

    Use client-side encryption with the Amazon S3 encryption client.

    Why it's wrong here

    The Amazon S3 encryption client performs client-side encryption, meaning data is encrypted before it ever reaches S3 Glacier, but the master key you use must be managed and rotated manually by your application. Even if you source the key from KMS, the client derives and caches data keys, and the server-side infrastructure of Glacier does not manage rotation on your behalf. This offloads encryption but does not deliver the required automatic key rotation, making it an incomplete solution.

  • ✗

    Use SSE-C with keys stored in AWS Secrets Manager and rotate keys annually.

    Why it's wrong here

    SSE-C lets you provide your own encryption keys for S3 Glacier, and S3 uses those keys to encrypt the object, but S3 neither stores nor rotates them. Storing keys in AWS Secrets Manager helps with secret management, but rotating annually via Secrets Manager is not automatic; you must build automation to call the rotation API and, critically, you must retain or re-encrypt data with old keys to maintain decryption. Because the requirement specifies automatic key rotation, SSE-C cannot meet it without significant custom work.

  • ✓

    Use the default encryption provided by S3 Glacier (SSE-S3).

    Why this is correct

    S3 Glacier’s default server-side encryption, SSE-S3, uses Amazon-managed AES-256 keys that AWS rotates automatically on a regular basis, typically about once a year. No customer effort is required to enable or manage this rotation, and it provides strong encryption of all objects at rest. This is the simplest solution that satisfies the automatic key rotation requirement, though it lacks the audit and permission flexibility of KMS customer-managed keys.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.