SCS-C02 Infrastructure Security Practice Question
A security engineer needs to ensure that all data stored in an Amazon S3 bucket is encrypted at rest. The bucket must use server-side encryption with a key managed by the customer (SSE-C). What must the engineer include in the PUT request to enforce this?
⚠ Common exam trap
Test-takers frequently confuse the `x-amz-server-side-encryption` header (used for SSE-S3 and SSE-KMS) with the SSE-C-specific headers, leading them to pick Option B or C, which do not allow customer-provided keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
x-amz-server-side-encryption-customer-algorithm and x-amz-server-side-encryption-customer-key
SSE-C requires the client to provide both the encryption algorithm and the encryption key in the PUT request headers. The `x-amz-server-side-encryption-customer-algorithm` header must be set to `AES256`, and the `x-amz-server-side-encryption-customer-key` header must contain the base64-encoded 256-bit key. Without these headers, S3 will not apply customer-provided encryption keys, and the object will not be encrypted with SSE-C.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
x-amz-server-side-encryption-customer-algorithm and x-amz-server-side-encryption-customer-key
Why this is correct
These two headers are mandatory for SSE-C, where the customer supplies the raw 256-bit AES key in each request rather than letting AWS hold key material. x-amz-server-side-encryption-customer-algorithm must be set to AES256, and x-amz-server-side-encryption-customer-key must contain the base64-encoded key, typically accompanied by x-amz-server-side-encryption-customer-key-MD5 to verify integrity. AWS discards the key after encrypting the object and stores only a salted HMAC for later validation, so you must re-supply these headers on every PUT, GET, HEAD, or range read.
- ✗
x-amz-server-side-encryption: AES256
Why it's wrong here
Setting x-amz-server-side-encryption: AES256 selects SSE-S3, a fully managed encryption mode in which AWS owns and manages the key hierarchy, generates a unique object key, and wraps it with a regularly rotated master key. This header carries only an algorithm identifier and contains no customer key material, so it cannot fulfill a requirement that the customer provide or control the encryption key. The request is visibly different from SSE-C because no x-amz-server-side-encryption-customer-* headers are present, and S3 does not require any customer-supplied key at all.
- ✗
x-amz-server-side-encryption: aws:kms
Why it's wrong here
The header x-amz-server-side-encryption: aws:kms invokes SSE-KMS, which uses AWS Key Management Service to generate a data key and encrypt it with a customer master key (CMK). While this gives you centralized audit and key rotation controls, KMS stores and manages the actual key material, so the customer never passes raw key bytes in the request. It also requires IAM permissions to use the KMS key and incurs per-request KMS charges, making it fundamentally different from SSE-C both in key custody and in the headers used.
- ✗
x-amz-server-side-encryption-bucket-key-enabled: true
Why it's wrong here
Setting x-amz-server-side-encryption-bucket-key-enabled: true activates S3 Bucket Keys, a cost-optimization feature for SSE-KMS that reduces KMS API calls by reusing a bucket-level key to wrap multiple object keys. This header does not select any encryption mode and does not supply or accept customer-provided key material; it only changes how the KMS key is used when SSE-KMS is already specified. It has no interaction with SSE-C, which requires the x-amz-server-side-encryption-customer-algorithm and x-amz-server-side-encryption-customer-key request headers to carry the customer's raw key.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.