SCS-C02 Data Protection Practice Question
A security engineer is designing a solution to encrypt data at rest in an Amazon DynamoDB table. The data must be encrypted with a customer managed key in AWS KMS that the security team can rotate annually. The DynamoDB table is used by an AWS Lambda function. Which approach should the engineer take to meet these requirements?
⚠ Common exam trap
The trap here is assuming that AWS managed keys or AWS owned keys can be rotated on a custom schedule, when in fact only customer managed keys support configurable automatic rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a customer managed KMS key, enable automatic key rotation with a one-year rotation period, and specify this key when creating the DynamoDB table.
Using a customer managed KMS key with automatic rotation set to one year gives the security team control over the key lifecycle. DynamoDB supports specifying a customer managed key at table creation. The Lambda function must have IAM permissions to use the key. This solution meets both the encryption and rotation requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a customer managed KMS key, enable automatic key rotation with a one-year rotation period, and specify this key when creating the DynamoDB table.
Why this is correct
A customer managed KMS key allows the security team to control rotation. Enabling automatic rotation with a one-year period meets the annual rotation requirement. When creating the DynamoDB table, specifying this key ensures all data is encrypted with it. The Lambda function's IAM role must have permissions to use the key for encrypt and decrypt operations.
- ✗
Enable DynamoDB encryption at rest with the default AWS owned key and configure annual rotation of that key.
Why it's wrong here
The default AWS owned key is managed by AWS and cannot be rotated by the customer. Rotation is automatic every three years and not configurable. This does not meet the requirement for customer managed annual rotation. Additionally, the key is not visible in the customer's account, so the security team cannot manage it.
- ✗
Enable DynamoDB encryption at rest with an AWS managed key and manually rotate the key every year using the AWS CLI.
Why it's wrong here
AWS managed keys cannot be manually rotated by the customer. Rotation is managed by AWS every three years. The security team cannot control the rotation schedule. This does not satisfy the requirement for annual rotation under the team's control. Also, manual rotation of AWS managed keys is not supported.
- ✗
Use AWS CloudHSM to generate a custom encryption key and configure DynamoDB to use that key for encryption at rest.
Why it's wrong here
DynamoDB encryption at rest integrates with AWS KMS, not directly with CloudHSM. While CloudHSM can be used as a custom key store for KMS, the key must still be a KMS key. DynamoDB cannot directly use a CloudHSM key. This approach adds unnecessary complexity and does not meet the requirement for annual rotation managed by the security team.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.