Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A security engineer is designing a solution to encrypt data at rest in an Amazon DynamoDB table. The data must be encrypted with a customer managed key in AWS KMS that the security team can rotate annually. The DynamoDB table is used by an AWS Lambda function. Which approach should the engineer take to meet these requirements?

⚠ Common exam trap

The trap here is assuming that AWS managed keys or AWS owned keys can be rotated on a custom schedule, when in fact only customer managed keys support configurable automatic rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a customer managed KMS key, enable automatic key rotation with a one-year rotation period, and specify this key when creating the DynamoDB table.

Using a customer managed KMS key with automatic rotation set to one year gives the security team control over the key lifecycle. DynamoDB supports specifying a customer managed key at table creation. The Lambda function must have IAM permissions to use the key. This solution meets both the encryption and rotation requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a customer managed KMS key, enable automatic key rotation with a one-year rotation period, and specify this key when creating the DynamoDB table.

    Why this is correct

    A customer managed KMS key allows the security team to control rotation. Enabling automatic rotation with a one-year period meets the annual rotation requirement. When creating the DynamoDB table, specifying this key ensures all data is encrypted with it. The Lambda function's IAM role must have permissions to use the key for encrypt and decrypt operations.

  • ✗

    Enable DynamoDB encryption at rest with the default AWS owned key and configure annual rotation of that key.

    Why it's wrong here

    The default AWS owned key is managed by AWS and cannot be rotated by the customer. Rotation is automatic every three years and not configurable. This does not meet the requirement for customer managed annual rotation. Additionally, the key is not visible in the customer's account, so the security team cannot manage it.

  • ✗

    Enable DynamoDB encryption at rest with an AWS managed key and manually rotate the key every year using the AWS CLI.

    Why it's wrong here

    AWS managed keys cannot be manually rotated by the customer. Rotation is managed by AWS every three years. The security team cannot control the rotation schedule. This does not satisfy the requirement for annual rotation under the team's control. Also, manual rotation of AWS managed keys is not supported.

  • ✗

    Use AWS CloudHSM to generate a custom encryption key and configure DynamoDB to use that key for encryption at rest.

    Why it's wrong here

    DynamoDB encryption at rest integrates with AWS KMS, not directly with CloudHSM. While CloudHSM can be used as a custom key store for KMS, the key must still be a KMS key. DynamoDB cannot directly use a CloudHSM key. This approach adds unnecessary complexity and does not meet the requirement for annual rotation managed by the security team.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.