Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

A security engineer needs to ensure that all data stored in a new Amazon DynamoDB table is encrypted at rest using a key that the company can manage, audit, and rotate. The company also wants to receive alerts if the key is used in an unauthorized way. Which solution meets these requirements with the LEAST operational effort?

⚠ Common exam trap

The trap here is thinking that AWS owned keys provide customer management, when they are fully managed by AWS and cannot be audited or rotated by the customer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AWS KMS customer managed keys with DynamoDB encryption at rest.

AWS KMS customer managed keys with DynamoDB encryption at rest provide customer control, auditability through CloudTrail, and automatic rotation with minimal effort. AWS owned keys lack customer control and auditing. Client-side encryption with Secrets Manager or CloudHSM introduces extra operational burden and does not integrate natively with DynamoDB encryption at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use AWS KMS customer managed keys with DynamoDB encryption at rest.

    Why this is correct

    DynamoDB encryption at rest integrates with AWS KMS, allowing the use of customer managed keys. This provides control over key policies, enables auditing via AWS CloudTrail, and supports automatic rotation. It requires minimal operational effort because DynamoDB manages the encryption and decryption transparently, and KMS handles key management, meeting all requirements.

  • ✗

    Use AWS CloudHSM to generate and store keys, and integrate with DynamoDB encryption.

    Why it's wrong here

    AWS CloudHSM provides dedicated HSMs but requires managing a cluster, client software, and high availability. DynamoDB does not natively integrate with CloudHSM for encryption at rest; you would need client-side encryption. This adds substantial operational effort and does not provide native DynamoDB encryption, making it unsuitable for the least-effort requirement.

  • ✗

    Enable DynamoDB encryption at rest with AWS owned keys.

    Why it's wrong here

    AWS owned keys are managed by AWS and not visible or controllable by the customer. The company cannot audit key usage, rotate the key, or set key policies. While this option requires no effort, it fails the requirements for customer management, auditing, and unauthorized-use alerts. Therefore, it is not suitable for this scenario.

  • ✗

    Implement client-side encryption using a key stored in AWS Secrets Manager.

    Why it's wrong here

    Client-side encryption requires the application to encrypt and decrypt data, adding significant development and operational overhead. While Secrets Manager can store the key, it does not provide native auditing of key usage for DynamoDB, and the company must build alerting for unauthorized use. This approach does not meet the least operational effort requirement.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.