Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

A company wants to protect sensitive data stored in Amazon S3 by encrypting it at rest. Which AWS service can be used to manage the encryption keys?

⚠ Common exam trap

SCS-C02 often tests the distinction between SSE-S3 (AWS-managed keys, no customer control) and SSE-KMS (customer-managed keys via KMS), and candidates must recognize that 'manage the encryption keys' implies KMS, not Secrets Manager or CloudHSM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Key Management Service (AWS KMS)

AWS Key Management Service (AWS KMS) is the AWS service designed to create, manage, rotate, and audit encryption keys used to protect data at rest in AWS services including Amazon S3. S3 server-side encryption with AWS KMS keys (SSE-KMS) integrates directly with KMS, giving the company centralized key management, granular IAM policies, key rotation, and CloudTrail audit logs of key usage. This is the correct answer for managing encryption keys for S3 data at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Secrets Manager

    Why it's wrong here

    AWS Secrets Manager is a purpose-built service for storing and rotating application credentials such as database passwords, API keys, and OAuth tokens. While it can use AWS KMS to encrypt those secrets, it is not a key management service and cannot generate or manage the keys used to encrypt objects in Amazon S3. For protecting S3 data, Secrets Manager would only store the keys to your system, not manage the encryption keys themselves.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    AWS CloudHSM provides dedicated hardware security modules (HSMs) that give you direct ownership of cryptographic keys stored in tamper-resistant hardware, but it is an HSM service, not a managed key management service. CloudHSM does not have a native integration with Amazon S3 server-side encryption, so you would need to build and operate custom client software and key storage. This makes CloudHSM overly complex for simple S3 encryption and it cannot offer the same centralized, automatic key control and audit trail as AWS KMS.

  • ✗

    AWS S3-managed keys (SSE-S3)

    Why it's wrong here

    SSE-S3 encrypts objects using unique data keys wrapped by a root key that AWS owns and rotates automatically, which requires no configuration from the customer. It does not allow you to manage or view the keys, define key policies, or disable the key for compliance purposes. If the company needs customer-controlled key management, separate permissioning, or auditability of key usage, SSE-S3 falls short because it removes all key control from the customer.

  • ✓

    AWS Key Management Service (AWS KMS)

    Why this is correct

    AWS KMS is a fully managed service for creating and controlling the encryption keys used across AWS services, and it natively integrates with Amazon S3 through SSE-KMS. You can create a customer managed key, define key policies and grants, set automatic annual rotation, and control access via IAM policies and key conditions. With envelope encryption, KMS protects each S3 object with a unique data key that is encrypted by your KMS key, allowing you to centrally manage, monitor, and revoke the master key while still receiving CloudTrail logs for every decrypt operation.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.