Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

Network Topology
$ aws cloudtrail lookup-eventslookup-attributes AttributeKey=EventNamemax-results 1Refer to the exhibit.```"Events": ["EventId": "example1","EventName": "Decrypt","EventTime": "2023-01-15T10:30:00Z","Username": "arn:aws:iam::123456789012:user/john.doe","Resources": ["ResourceType": "AWS::KMS::Key","ResourceName": "arn:aws:kms:us-east-1:123456789012:key/abc123"

A security engineer is investigating a potential data breach and finds this CloudTrail log entry. What does this entry indicate?

⚠ Common exam trap

The trap here is that candidates see a KMS-related CloudTrail entry and assume encryption or key deletion, when the specific eventName (Decrypt) is the decisive detail that must be read carefully.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A user decrypted data using a KMS key

The CloudTrail entry shows a Decrypt API call against a KMS key, which indicates a principal used the key to decrypt ciphertext. This is the standard CloudTrail event emitted when KMS performs a cryptographic decryption operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A user encrypted data using a KMS key

    Why it's wrong here

    An Encrypt event would indicate the creation of ciphertext, not data exposure or unauthorized disclosure. In this investigation, the recorded CloudTrail event is specifically named 'Decrypt', so a user calling the Encrypt API action does not match the event in question and would not be the cause of the suspected breach.

  • ✓

    A user decrypted data using a KMS key

    Why this is correct

    The wrong options are eliminated because this is a Decrypt event: a user invoked the KMS Decrypt API to reveal plaintext from previously encrypted data. In an investigation, this event is significant because it shows the KMS key was used to turn ciphertext into plaintext, which is how an attacker or insider would access data after exfiltrating it. Therefore, this interpretation correctly matches the CloudTrail record and indicates a potential data disclosure.

  • ✗

    An anonymous user accessed the KMS key

    Why it's wrong here

    KMS events are never anonymous; CloudTrail captures the IAM principal ARN (user, role, or federated identity) for every KMS API call. Moreover, there is no 'accessing a key' event—KMS actions are discrete API operations like Decrypt or DescribeKey—so this option is both factually incorrect about identity and too vague about the operation, making it an improper explanation for the Decrypt event.

  • ✗

    The KMS key was deleted

    Why it's wrong here

    If the KMS key had been deleted, CloudTrail would record a ScheduledDeletion or DeleteKey event, not a Decrypt event. KMS key deletion is a deliberate, delayed process with its own event names and does not directly return plaintext data. Since the observed event is Decrypt, this option describes a different, unrelated action and is therefore incorrect.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.