Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

Network Topology
aws kms encryptkey-id 1234abcd-12ab-34cd-56ef-1234567890abplaintext fileb://secret.txtoutput textquery CiphertextBlobdecode > encrypted_secret.txtRefer to the exhibit.

A security engineer runs the command shown in the exhibit. What is the primary purpose of this command?

⚠ Common exam trap

The trap is confusing the KMS Encrypt API with other KMS operations like GenerateDataKey or ReEncrypt. Candidates might think the command is for generating a data key or re-encrypting, but the presence of '--plaintext fileb://' clearly indicates encryption of plaintext data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To encrypt the contents of secret.txt using a KMS key and store the result in encrypted_secret.txt.

The command shown in the exhibit is 'aws kms encrypt --key-id <key-id> --plaintext fileb://secret.txt --output text --query CiphertextBlob | base64 --decode > encrypted_secret.txt'. This command uses the AWS KMS Encrypt API to encrypt the contents of secret.txt with the specified KMS key, then decodes the base64-encoded ciphertext and writes it to encrypted_secret.txt. Therefore, the primary purpose is to encrypt the file contents using a KMS key and store the result in encrypted_secret.txt.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To generate a data key without plaintext.

    Why it's wrong here

    Generating a data key without plaintext is handled by the `GenerateDataKeyWithoutPlaintext` API, which returns only an encrypted data key (a ciphertext blob) and deliberately omits the plaintext key to keep the key material protected. That operation does not encrypt a user-supplied file; it creates a key for envelope encryption. The command in the exhibit directly encrypts the contents of secret.txt with a KMS key and stores the encrypted result, not a separately generated data key.

  • ✗

    To re-encrypt an existing encrypted file under a new key.

    Why it's wrong here

    Re-encrypting an existing encrypted file under a new key is performed by the `ReEncrypt` API, which accepts an existing ciphertext blob, decrypts it with the old key, then encrypts the same plaintext with a different KMS key. The command shown takes a plaintext file (secret.txt) and outputs ciphertext to encrypted_secret.txt, so it performs an initial encryption of plaintext rather than re-encrypting already-encrypted data.

  • ✗

    To decrypt the file secret.txt using a KMS key.

    Why it's wrong here

    Decrypting secret.txt would require the `aws kms decrypt` API, which takes ciphertext as input and returns plaintext using the KMS key that originally encrypted it or a key specified in the call. The command in the exhibit instead supplies a plaintext file (secret.txt) to the encryption operation and writes the resulting ciphertext to encrypted_secret.txt, so it reverses the actual direction of the operation.

  • ✓

    To encrypt the contents of secret.txt using a KMS key and store the result in encrypted_secret.txt.

    Why this is correct

    The command invokes the KMS Encrypt API by taking the plaintext bytes from secret.txt, sending them with the specified key ID, and writing the returned base64-encoded `CiphertextBlob` to encrypted_secret.txt. This is the direct encryption of the file's contents under the given KMS key, producing ciphertext that can later be decrypted only with the same key (and any required encryption context). Because KMS Encrypt accepts plaintext up to only 4 KB, this approach is appropriate for small secrets like passwords or configuration values, not for large files.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.