Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

A financial company uses AWS KMS to encrypt sensitive data. The security team notices that a KMS key has been deleted, but the encrypted data is still needed for a short period. What is the fastest way to make the data decryptable again?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cancel the key deletion within the waiting period

When a KMS key is scheduled for deletion, there is a waiting period (7-30 days) during which the deletion can be cancelled, restoring the key and making the data decryptable. Option A is incorrect because AWS Support cannot recover a deleted KMS key. Option C is incorrect because CloudHSM backups are unrelated to KMS key material. Option D is incorrect because re-encrypting with a new key would require the original key to decrypt first.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Contact AWS Support to recover the key material

    Why it's wrong here

    AWS Support has no mechanism to recover or restore deleted KMS key material because customer master keys are protected by FIPS-validated hardware and the key material is never exportable or retrievable by AWS. Once a KMS key is scheduled for deletion, only the account owner can cancel the deletion during the waiting period; Support cannot access the key or reverse the scheduled deletion. Therefore, contacting Support is futile for data encrypted under a deleted key.

  • ✓

    Cancel the key deletion within the waiting period

    Why this is correct

    When a customer-managed KMS key is scheduled for deletion, KMS enforces a mandatory waiting period (7 to 30 days, configurable) during which the key can be restored using the CancelKeyDeletion operation, which returns the key to its previous enabled state. As long as the original key is restored before the deletion completes, any ciphertext encrypted under that key—including data keys wrapped by the key—remains decryptable, so your data is not lost. The waiting period is designed exactly for this recovery scenario; after it expires, deletion is irreversible and no recovery path exists.

  • ✗

    Restore the key from a CloudHSM backup

    Why it's wrong here

    AWS KMS does not use AWS CloudHSM as its backing store; KMS maintains customer master keys in a fleet of FIPS 140-2 validated hardware security modules that are managed exclusively by the AWS KMS service, not by the customer. Restoring a CloudHSM backup only recreates keys that the customer originally created in their own CloudHSM cluster, which have no relationship to KMS key material or to the KMS key used for your data. Therefore, a CloudHSM backup cannot provide the original KMS key needed to decrypt your ciphertext.

  • ✗

    Re-encrypt the data with a new KMS key

    Why it's wrong here

    Re-encrypting data with a new KMS key is only possible if you can first decrypt the existing ciphertext, because KMS' Decrypt and ReEncrypt operations require the original KMS key to be enabled and accessible. Once the key is permanently deleted, the underlying plaintext is unrecoverable, so you cannot read the data to re-encrypt it under a new key. Creating a new KMS key protects new data written going forward, but it does nothing to recover ciphertext that was encrypted under the deleted key.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.