Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A security engineer needs to encrypt a 10 GB file before uploading it to Amazon S3. The encryption must use a customer managed key in AWS KMS, and the engineer wants to minimize the amount of data sent to KMS for encryption. Which approach should the engineer use?

⚠ Common exam trap

The trap here is assuming that KMS can directly encrypt large files, when in fact the Encrypt API has a 4 KB limit, necessitating envelope encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the AWS Encryption SDK with a customer managed KMS key to encrypt the file locally, then upload the encrypted file to S3.

The AWS Encryption SDK implements envelope encryption locally, using a KMS customer managed key only to encrypt a data key. This minimizes data sent to KMS because only the small data key is transmitted. The encrypted file is then uploaded to S3. This meets the requirements for local encryption and efficient KMS usage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Upload the file to S3 using SSE-KMS with the customer managed key, which encrypts the entire file with KMS.

    Why it's wrong here

    SSE-KMS also uses envelope encryption, but the encryption happens server-side after upload. The entire file is sent to S3, not to KMS. However, the requirement is to encrypt before uploading and minimize data sent to KMS. SSE-KMS does not involve sending the file to KMS, but it also does not allow local encryption. The question specifies encrypting before upload, so this option does not meet that.

  • ✗

    Use the KMS Encrypt API directly to encrypt the entire file with the customer managed key, then upload the encrypted file to S3.

    Why it's wrong here

    The KMS Encrypt API is limited to 4 KB of data. A 10 GB file cannot be encrypted directly with KMS Encrypt. This would fail. The correct approach is to use envelope encryption, where KMS encrypts a data key, not the entire file. Sending the entire file to KMS is not possible and would be inefficient.

  • ✓

    Use the AWS Encryption SDK with a customer managed KMS key to encrypt the file locally, then upload the encrypted file to S3.

    Why this is correct

    The AWS Encryption SDK uses envelope encryption: it generates a data key, encrypts the file with that data key, and encrypts the data key with the KMS customer managed key. Only the small data key is sent to KMS, minimizing data transfer. The encrypted file and encrypted data key are stored together. This meets the requirement to minimize data sent to KMS.

  • ✗

    Use S3 client-side encryption with a customer provided key (SSE-C) and store the key in AWS KMS.

    Why it's wrong here

    SSE-C uses a customer provided key that the client manages. AWS KMS is not involved in SSE-C; the key is provided with each request. Storing the key in KMS does not integrate with SSE-C. This approach does not use a customer managed KMS key for encryption and does not minimize data sent to KMS because KMS is not used. It also requires managing the key outside of KMS.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.