SCS-C02 Data Protection Practice Question
A company wants to protect data stored in Amazon S3 Glacier. The data must be encrypted at rest and the encryption keys must be rotated annually. Which TWO options meet these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use SSE-KMS with a customer-managed key that has automatic key rotation enabled.
SSE-KMS with a customer-managed key that has automatic key rotation enabled allows annual rotation and meets the encryption requirement. Option E is correct because S3 Glacier's default encryption, SSE-S3, encrypts data at rest and AWS manages key rotation automatically on an annual basis. Option B is incorrect because AWS CloudHSM requires manual key rotation. Option C is incorrect because client-side encryption with the Amazon S3 encryption client does not use server-side encryption and requires manual key management. Option D is incorrect because SSE-C requires you to manage and rotate the keys manually.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use SSE-KMS with a customer-managed key that has automatic key rotation enabled.
Why this is correct
SSE-KMS with a customer-managed AWS KMS key that has automatic rotation enabled satisfies the requirement because S3 Glacier applies server-side encryption using KMS, and KMS automatically rotates the underlying key material on an annual basis without any manual action. The CMK remains the same logical key, so object references and permissions are unchanged while the encryption material is refreshed, meeting compliance policies that demand automatic key rotation. This is the most flexible option when you need separate permissions and audit trails.
- ✗
Use AWS CloudHSM to generate a key and encrypt data before uploading to Glacier.
Why it's wrong here
AWS CloudHSM provides hardware-based cryptographic key generation and client-side encryption before upload to Glacier, but it does not offer automatic key rotation. Your application must orchestrate creating new keys, re-encrypting existing objects, and deleting old keys, which is manual and error-prone. Moreover, Glacier itself cannot use CloudHSM keys for server-side encryption; you are responsible for the entire key lifecycle, so this approach fails the automatic rotation requirement.
- ✗
Use client-side encryption with the Amazon S3 encryption client.
Why it's wrong here
The Amazon S3 encryption client performs client-side encryption, meaning data is encrypted before it ever reaches S3 Glacier, but the master key you use must be managed and rotated manually by your application. Even if you source the key from KMS, the client derives and caches data keys, and the server-side infrastructure of Glacier does not manage rotation on your behalf. This offloads encryption but does not deliver the required automatic key rotation, making it an incomplete solution.
- ✗
Use SSE-C with keys stored in AWS Secrets Manager and rotate keys annually.
Why it's wrong here
SSE-C lets you provide your own encryption keys for S3 Glacier, and S3 uses those keys to encrypt the object, but S3 neither stores nor rotates them. Storing keys in AWS Secrets Manager helps with secret management, but rotating annually via Secrets Manager is not automatic; you must build automation to call the rotation API and, critically, you must retain or re-encrypt data with old keys to maintain decryption. Because the requirement specifies automatic key rotation, SSE-C cannot meet it without significant custom work.
- ✓
Use the default encryption provided by S3 Glacier (SSE-S3).
Why this is correct
S3 Glacier’s default server-side encryption, SSE-S3, uses Amazon-managed AES-256 keys that AWS rotates automatically on a regular basis, typically about once a year. No customer effort is required to enable or manage this rotation, and it provides strong encryption of all objects at rest. This is the simplest solution that satisfies the automatic key rotation requirement, though it lacks the audit and permission flexibility of KMS customer-managed keys.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.