SCS-C02 Data Protection Practice Question
A financial services company is designing a data protection strategy for its DynamoDB table containing sensitive customer data. The table has a global secondary index (GSI). The company needs to encrypt the data at rest using a customer managed key (CMK) that is rotated annually. Which solution meets these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create the table with a customer managed key (CMK) and enable automatic key rotation
DynamoDB supports encryption at rest using AWS KMS. When a table is created, you must specify whether to use a default AWS managed key or a customer managed key (CMK). The global secondary index (GSI) inherits the encryption settings from the base table and cannot have separate encryption settings. Option D is correct because you can create the table with a CMK and enable automatic key rotation on that CMK. Option A is incorrect because you cannot change the encryption key of an existing DynamoDB table; encryption settings must be specified at creation. Option B is incorrect because DynamoDB tables always have encryption enabled by default (you cannot create a table without encryption), and you cannot enable encryption separately on the GSI. Option C is incorrect because the requirement specifies a customer managed key (CMK), not an AWS managed key; while AWS managed keys have automatic rotation by default, they do not provide customer control over the key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create the table with default encryption, then update the table to use a CMK and enable automatic rotation
Why it's wrong here
DynamoDB encryption at rest is determined at table creation time and cannot be changed afterward; the table cannot be updated from the default AWS owned key to a CMK. Any attempt to modify the encryption key on an existing table is unsupported, so the scenario of creating with default encryption and later updating is invalid. Additionally, GSIs would inherit the original default settings, making this approach non-compliant with the requirement.
- ✗
Create the table without encryption, then enable encryption on the table and GSI separately using a CMK
Why it's wrong here
DynamoDB does not allow creating a table without encryption; encryption at rest is always enabled, using an AWS owned key if no other key is specified. Moreover, encryption settings cannot be enabled or changed on an existing table, and GSIs do not have independent encryption configurations — they automatically use the table's encryption key. Thus, the proposed two-step enablement of the table and GSI separately is both technically impossible and unnecessary.
- ✗
Create the table with an AWS managed key and use AWS KMS automatic rotation
Why it's wrong here
Although AWS managed KMS keys used by DynamoDB are rotated automatically, the rotation policy and key material are controlled entirely by AWS, giving the customer no ability to customize, audit, or manage the key. Financial services compliance requirements often demand customer-controlled keys with explicit rotation policies to ensure the organization retains governance over data protection. An AWS managed key does not provide the required control, so it fails the stated requirement even though automatic rotation does occur.
- ✓
Create the table with a customer managed key (CMK) and enable automatic key rotation
Why this is correct
A customer managed CMK is the correct choice because the customer controls the key, including its rotation schedule, access policies, and auditability, which meets financial services compliance demands. When you create a DynamoDB table with a customer managed CMK and enable automatic key rotation, DynamoDB uses that key to encrypt the base table and all GSIs automatically, as GSIs inherit the table's encryption settings. This provides unified, customer-controlled encryption with rotation, fully satisfying the requirement.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.