SCS-C02 Data Protection Practice Question
A security engineer is configuring AWS KMS to encrypt data in a new Amazon S3 bucket. The company requires that the KMS key used for encryption automatically rotate its key material every year, and that the rotation be transparent to applications. The engineer creates a customer managed key with key spec SYMMETRIC_DEFAULT and key usage ENCRYPT_DECRYPT. What should the engineer do next to meet the requirement?
⚠ Common exam trap
The trap here is assuming that automatic key rotation changes the key ID or ARN, or that it is available for all key types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic key rotation on the customer managed key.
AWS KMS customer managed symmetric keys support automatic annual rotation of the backing key material while preserving the same key ID and ARN. This allows existing applications and policies to continue using the key without modification. Enabling automatic rotation satisfies the requirement for transparent yearly rotation. Other options either require manual key replacement, use a key type that does not support rotation, or rely on an AWS managed key that cannot be configured by the customer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable automatic key rotation on the customer managed key.
Why this is correct
Automatic key rotation is a feature of AWS KMS customer managed keys that rotates the backing key material annually while retaining the same key ID and ARN. Applications continue to use the same key identifier, and AWS KMS automatically uses the new material for new encryption operations. This meets the requirement for transparent yearly rotation without application changes. The rotation is managed by AWS KMS and requires no additional infrastructure.
- ✗
Enable automatic key rotation on the AWS managed key aws/s3.
Why it's wrong here
AWS managed keys, such as aws/s3, are managed by AWS and do not support customer-controlled automatic key rotation settings. Their rotation is handled by AWS on a schedule that the customer cannot configure. The scenario requires the engineer to control rotation, which is only possible with customer managed keys. Therefore, using an AWS managed key does not meet the requirement.
- ✗
Use an asymmetric KMS key with RSA_2048 and enable automatic rotation.
Why it's wrong here
Asymmetric KMS keys do not support automatic key rotation. Only symmetric customer managed keys with ENCRYPT_DECRYPT usage support automatic rotation. Additionally, asymmetric keys are typically used for encryption outside AWS KMS or for digital signatures, not for direct S3 server-side encryption. The requirement is for transparent yearly rotation, which asymmetric keys cannot provide in this context.
- ✗
Create a new customer managed key each year and update the S3 bucket policy to use the new key.
Why it's wrong here
Creating a new key annually and updating the bucket policy would change the key ID and ARN, requiring applications and policies to be updated. This is not transparent and can cause access issues for existing objects encrypted with the old key. It also adds operational overhead and does not provide automatic rotation. AWS KMS automatic rotation is the intended solution for this requirement.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.