SCS-C02 Data Protection Practice Question
A security engineer is configuring AWS KMS for a multi-Region application that uses Amazon S3 and Amazon RDS in us-east-1 and eu-west-1. The company requires that encryption keys be available in both Regions and that data encrypted in one Region can be decrypted in the other without re-encrypting. The company also wants to minimize latency for cryptographic operations. Which solution meets these requirements?
⚠ Common exam trap
The trap here is assuming that a single KMS key can be used across Regions, when KMS keys are strictly regional and multi-Region keys are required for cross-Region decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use AWS KMS multi-Region keys with a primary key in us-east-1 and a replica in eu-west-1.
AWS KMS multi-Region keys allow the same key material to be used in multiple Regions, so data encrypted in one Region can be decrypted in another without re-encryption. Creating a primary key and a replica in the second Region provides availability and low-latency access. Single-Region keys, CloudHSM replication, and rotation do not meet the cross-Region decryption requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an AWS CloudHSM cluster in each Region and replicate keys between them.
Why it's wrong here
CloudHSM clusters are regional and do not automatically replicate keys across Regions. While you can manually copy keys, this adds significant operational overhead and does not integrate natively with S3 or RDS encryption. It also does not provide the same seamless cross-Region decryption as multi-Region KMS keys, and latency depends on cluster configuration.
- ✗
Enable automatic key rotation on a single KMS key and use it in both Regions.
Why it's wrong here
A single KMS key cannot be used in multiple Regions; KMS keys are strictly regional. Enabling rotation does not change the key's Region or make it available elsewhere. This option does not provide cross-Region key availability or decryption, and it would require re-encrypting data, violating the requirement to avoid re-encryption.
- ✓
Use AWS KMS multi-Region keys with a primary key in us-east-1 and a replica in eu-west-1.
Why this is correct
Multi-Region keys are a set of interoperable KMS keys in different Regions that share the same key material and key ID. They allow data encrypted in one Region to be decrypted in another without re-encryption. Creating a primary key and a replica in the second Region provides availability and low-latency access, meeting all requirements.
- ✗
Create a customer managed key in us-east-1 and grant cross-Region access to principals in eu-west-1.
Why it's wrong here
AWS KMS keys are regional and cannot be used directly in another Region, even with cross-Region IAM policies. A key created in us-east-1 cannot decrypt data in eu-west-1 because KMS endpoints are regional. This approach does not provide key availability in both Regions and would require re-encrypting data, failing the requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.