Courseiva

CCNA Data Protection Questions

75 of 176 questions · Page 1/3 · Data Protection · Answers revealed

1
Multi-Selecthard

A company is designing a data protection strategy for its Amazon S3 bucket that stores sensitive customer data. The bucket must be encrypted at rest using a customer managed key (CMK) that is stored in AWS KMS. The company also needs to ensure that only authorized users can decrypt objects. Which TWO actions should the company take?

Select 2 answers
A.Create a bucket policy that denies s3:GetObject unless the request includes a specific encryption context
B.Modify the KMS key policy to allow only the authorized IAM roles to use the key
C.Attach an IAM policy to the authorized users that grants kms:Decrypt on the CMK
D.Create a VPC endpoint for S3 and use bucket policies to restrict access to the endpoint
E.Use SSE-C with a customer-provided key
AnswersB, C

Modifying the KMS key policy is the correct approach because the key policy is the resource-based policy that directly controls which principals can call kms:Decrypt on the CMK. By explicitly listing only authorized IAM roles as principals with Decrypt permission, you ensure that even if an S3 bucket policy or object ACL grants read access to ciphertext, those roles cannot decrypt it without the key. This is a robust data protection strategy because it combines S3 access control with KMS key-level authorization.

Why this answer

Option B is correct because the KMS key policy is the primary resource-based access control for a customer managed key, so modifying it to allow only the authorized IAM roles to use the key ensures that no other principals can call kms:Decrypt or otherwise use the CMK to access the encrypted S3 objects. Option C is correct because even if the key policy permits a role, the caller still needs an identity-based IAM policy granting kms:Decrypt on that specific CMK, so attaching such a policy to the authorized users is required for them to decrypt the objects. Together, the key policy and the IAM policy satisfy the requirement that only authorized users can decrypt data encrypted with the CMK.

Option A does not belong because S3 server-side encryption with KMS does not use encryption context in the s3:GetObject request in the way described, and denying based on encryption context is not the mechanism for restricting decryption to authorized users. Option D does not belong because a VPC endpoint and bucket policy control network/API access to S3, not who can decrypt with the KMS CMK. Option E does not belong because SSE-C uses a customer-provided key rather than a CMK stored in AWS KMS, which contradicts the stated requirement.

Exam trap

SCS-C02 often tests the dual requirement of KMS key policies and IAM policies — candidates may pick only one, forgetting that both must allow the action for access to be granted.

2
MCQhard

A financial services company must ensure that all data at rest in Amazon RDS for PostgreSQL is encrypted. The current database is unencrypted. What is the MOST operationally efficient way to enable encryption?

A.Export the database to S3 using pg_dump, then import into a new encrypted RDS instance.
B.Create a read replica with encryption enabled and promote it to primary.
C.Take a snapshot of the database, copy the snapshot with encryption enabled, and restore the encrypted snapshot to a new DB instance.
D.Enable encryption directly on the existing RDS instance by modifying the DB instance settings.
AnswerC

This is the officially supported AWS method for adding encryption at rest to an existing unencrypted RDS instance. You take a manual snapshot, copy that snapshot while specifying a KMS key (which encrypts the snapshot copy), and then restore the encrypted snapshot to a new DB instance. The restored instance is encrypted at the storage layer, and you can repoint your application to its new endpoint before decommissioning the original instance. After creation, encryption on that restored instance cannot be disabled.

Why this answer

The most operationally efficient way to enable encryption on an existing unencrypted RDS for PostgreSQL database is to take a snapshot, copy the snapshot with encryption enabled, and restore it to a new encrypted DB instance. This method leverages RDS's native snapshot and restore capabilities, minimizing manual intervention and downtime. Other methods like exporting and importing data are more complex and time-consuming, and encryption cannot be enabled directly on an existing instance.

Exam trap

SCS-C02 often tests the method to encrypt an existing unencrypted RDS instance, and candidates may incorrectly believe that encryption can be enabled by modifying the instance or by creating a read replica.

How to eliminate wrong answers

Option A is wrong because exporting and importing via pg_dump is manual, error-prone, and requires significant downtime. Option B is wrong because creating an encrypted read replica is not possible if the source is unencrypted; encryption must be enabled at creation, and you cannot enable encryption on a read replica of an unencrypted instance. Option D is wrong because RDS does not allow enabling encryption on an existing DB instance; encryption can only be enabled at creation or by restoring from an encrypted snapshot.

3
MCQhard

A company uses AWS Secrets Manager to store database credentials for an application running on EC2 instances. The security engineer needs to ensure that the credentials are automatically rotated every 30 days and that the application can retrieve the credentials without hardcoding them. The engineer has configured a rotation Lambda function and enabled rotation. However, the application is still using hardcoded credentials. What should the engineer do to ensure the application retrieves credentials dynamically?

A.Use AWS AppConfig to deploy the credentials to the EC2 instances and configure the application to read from a local file.
B.Modify the application code to call the Secrets Manager GetSecretValue API using the AWS SDK, and grant the EC2 instance role permission to access the secret.
C.Store the credentials in AWS Systems Manager Parameter Store as a SecureString parameter and modify the application to retrieve them from there.
D.Configure the application to read the credentials from an environment variable that is updated by the rotation Lambda function.
AnswerB

To retrieve credentials dynamically, the application must use the Secrets Manager API to fetch the secret at runtime. This requires code changes to call GetSecretValue and appropriate IAM permissions for the EC2 instance role to access the secret. This approach eliminates hardcoded credentials and allows automatic rotation to take effect without application changes.

Why this answer

The application must be modified to use the Secrets Manager API to retrieve credentials at runtime. This ensures that the application always gets the current credentials after rotation. The EC2 instance role must have permissions to call GetSecretValue on the secret.

This is the standard pattern for dynamic secret retrieval.

Exam trap

The trap here is thinking that enabling rotation in Secrets Manager automatically updates the application's credentials, but the application must be coded to fetch the secret dynamically.

4
Multi-Selecteasy

A company is storing sensitive data in Amazon S3. They want to ensure that all data is encrypted at rest using server-side encryption. Which THREE options are available for server-side encryption in S3? (Select THREE.)

Select 3 answers
A.Client-side encryption
B.SSE-KMS
C.SSE-S3
D.SSE-C
E.AWS CloudHSM
AnswersB, C, D

SSE-KMS integrates Amazon S3 with AWS Key Management Service to perform server-side encryption using envelope encryption: S3 calls KMS to generate a data key, encrypts the object with it, and stores the encrypted data key alongside the object. It supports customer-managed KMS keys, enabling granular access control through IAM and KMS policies, automatic key rotation, and audit logs via CloudTrail. This makes it particularly suitable for sensitive data requiring separation of duties and compliance traceability, though it is only one of several valid S3 server-side encryption options.

Why this answer

SSE-KMS (B) is a valid S3 server-side encryption option in which S3 encrypts objects using keys managed by AWS KMS, giving you control over key policies, audit trails via CloudTrail, and separation of permissions. SSE-S3 (C) is also correct: S3 manages the encryption keys entirely with AES-256, and it is the default server-side encryption applied to objects at rest. SSE-C (D) is correct as well: the customer provides the encryption key on each request, and S3 performs the encryption/decryption server-side without storing the key.

Client-side encryption (A) is not server-side encryption because data is encrypted before it reaches S3, so S3 never performs the encryption. AWS CloudHSM (E) is a dedicated hardware security module service, not an S3 server-side encryption option, though it can be used with SSE-C or custom key management.

Exam trap

SCS-C02 often tests the distinction between server-side and client-side encryption — candidates may incorrectly include client-side encryption or CloudHSM as S3 SSE options.

5
MCQeasy

A company stores sensitive customer data in Amazon S3. They want to ensure that all objects are encrypted at rest using server-side encryption with AWS KMS. Which S3 bucket policy statement should be added to deny uploads that do not request SSE-KMS?

A.Deny PutObject unless 's3:x-amz-server-side-encryption' is 'AES256'
B.Deny PutObject unless 's3:x-amz-server-side-encryption' is 'aws:kms'
C.Deny PutObject unless 'aws:SourceArn' equals the bucket ARN
D.Deny PutObject unless 's3:x-amz-server-side-encryption-aws-kms-key-id' is present
AnswerB

This is the correct condition because it explicitly requires the s3:x-amz-server-side-encryption header to carry the value aws:kms. In a bucket policy, a Deny with this condition rejects any PutObject call that is not using SSE-KMS, thereby enforcing KMS encryption on all stored objects. It targets the encryption mode directly and avoids the ambiguity of key-ID or source-based checks.

Why this answer

The condition 's3:x-amz-server-side-encryption' with value 'aws:kms' enforces that objects are uploaded with SSE-KMS. Option A is incorrect because 'AES256' enforces SSE-S3, not SSE-KMS. Option C is incorrect because 'aws:SourceArn' is used for cross-account access, not encryption enforcement.

Option D is incorrect because requiring the specific KMS key ID is too restrictive; the policy should only require the encryption type, not a particular key.

6
MCQmedium

A security engineer is configuring AWS KMS to encrypt data in a new Amazon S3 bucket. The company requires that the KMS key used for encryption automatically rotate its key material every year, and that the rotation be transparent to applications. The engineer creates a customer managed key with key spec SYMMETRIC_DEFAULT and key usage ENCRYPT_DECRYPT. What should the engineer do next to meet the requirement?

A.Enable automatic key rotation on the customer managed key.
B.Enable automatic key rotation on the AWS managed key aws/s3.
C.Use an asymmetric KMS key with RSA_2048 and enable automatic rotation.
D.Create a new customer managed key each year and update the S3 bucket policy to use the new key.
AnswerA

Automatic key rotation is a feature of AWS KMS customer managed keys that rotates the backing key material annually while retaining the same key ID and ARN. Applications continue to use the same key identifier, and AWS KMS automatically uses the new material for new encryption operations. This meets the requirement for transparent yearly rotation without application changes. The rotation is managed by AWS KMS and requires no additional infrastructure.

Why this answer

AWS KMS customer managed symmetric keys support automatic annual rotation of the backing key material while preserving the same key ID and ARN. This allows existing applications and policies to continue using the key without modification. Enabling automatic rotation satisfies the requirement for transparent yearly rotation.

Other options either require manual key replacement, use a key type that does not support rotation, or rely on an AWS managed key that cannot be configured by the customer.

Exam trap

The trap here is assuming that automatic key rotation changes the key ID or ARN, or that it is available for all key types.

7
MCQhard

A company uses AWS CloudHSM to generate and store encryption keys for a custom application. The security team needs to ensure high availability and durability of the keys. Which architecture should be recommended?

A.Use AWS KMS instead of CloudHSM for better durability
B.Deploy a single CloudHSM instance in one Availability Zone
C.Deploy CloudHSM in two AWS Regions with automatic replication
D.Deploy a CloudHSM cluster with at least two HSMs in different Availability Zones
AnswerD

Creating a CloudHSM cluster with at least two HSMs in different Availability Zones ensures that if one HSM or AZ becomes unavailable, the other HSM can continue serving cryptographic operations. CloudHSM automatically synchronizes users, keys, and policies across all HSMs in the cluster, so the remaining HSM has the same key material. This architecture provides redundancy, high availability, and aligns with AWS recommended best practices for CloudHSM. Hence, it is the correct answer for improving durability/availability while keeping the HSM-based control.

Why this answer

Deploying a CloudHSM cluster with at least two HSMs in different Availability Zones provides high availability and durability. CloudHSM automatically synchronizes keys across HSMs in the cluster, so if one HSM fails, the others continue to provide access to the keys.

Exam trap

SCS-C02 often tests the misconception that CloudHSM automatically replicates across regions, but it does not; candidates may also think that a single HSM is sufficient for high availability.

How to eliminate wrong answers

Option A is wrong because while KMS provides high durability, the requirement is to use CloudHSM for key generation and storage, so switching to KMS does not meet the requirement. Option B is wrong because a single HSM in one AZ is a single point of failure and does not provide high availability. Option C is wrong because CloudHSM does not support automatic replication across regions; you must manually copy keys or use other methods, and cross-region replication is not automatic.

8
Multi-Selecthard

A company is designing a data protection strategy for Amazon S3. The compliance team requires that all objects be encrypted at rest and that any attempt to upload an unencrypted object be blocked. Which TWO steps should the company take? (Choose TWO.)

Select 2 answers
A.Enable default encryption on the bucket with SSE-S3 or SSE-KMS.
B.Add a bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header.
C.Enable S3 Object Lock.
D.Enable S3 Transfer Acceleration.
E.Enable S3 Block Public Access.
AnswersA, B

Enabling default encryption on the bucket with SSE-S3 or SSE-KMS ensures every object placed in S3 is automatically encrypted at rest, even if the client does not send an encryption header. SSE-S3 uses AES-256 managed by AWS, while SSE-KMS uses envelope encryption with a customer-managed KMS key, giving you auditability, key rotation, and fine-grained access control. This is the simplest baseline measure to satisfy typical encryption-at-rest requirements for a new S3 data protection strategy.

Why this answer

Option A is correct because enabling default encryption on the bucket with SSE-S3 or SSE-KMS ensures that every object stored in the bucket is automatically encrypted at rest, satisfying the compliance requirement for encryption of all objects. Option B is correct because a bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header actively blocks any attempt to upload an object without server-side encryption, enforcing encryption at upload time. Together, these two steps provide both automatic encryption and a preventive control against unencrypted uploads.

Option C is not correct because S3 Object Lock provides WORM protection and retention, not encryption enforcement. Option D is not correct because S3 Transfer Acceleration only improves upload performance over long distances. Option E is not correct because S3 Block Public Access prevents public exposure of objects, not unencrypted uploads.

Exam trap

SCS-C02 often tests the difference between default encryption and enforced encryption, and candidates may think that enabling default encryption alone blocks unencrypted uploads, but it does not; a bucket policy is required to deny unencrypted PUT requests.

9
MCQhard

A company uses AWS Secrets Manager to store database credentials. The security team needs to ensure that secrets are automatically rotated every 30 days. The rotation function must be implemented with minimal operational overhead. Which approach should be used?

A.Create an Amazon EventBridge rule that triggers a Lambda function to rotate the secret
B.Use AWS CLI to schedule a cron job that runs every 30 days and rotates the secret
C.Use Amazon CloudWatch Events to invoke an AWS Lambda function that updates the secret
D.Enable automatic rotation in Secrets Manager and configure the rotation interval to 30 days
AnswerD

Enabling automatic rotation in Secrets Manager with a 30-day interval is the correct managed solution. Secrets Manager schedules the rotation, invokes the configured Lambda rotation function, and coordinates the change of the database password with the secret's version lifecycle using AWSCURRENT and AWSPREVIOUS staging labels. You simply choose the rotation interval, and the service handles all scheduling, retries, and permissions, providing the lowest operational overhead. This also works with common database services like RDS via the built-in rotation templates.

Why this answer

AWS Secrets Manager has native, built-in rotation support that requires only enabling rotation and specifying a rotation interval and a Lambda rotation function (AWS provides templates for RDS, Redshift, DocumentDB, etc.). Setting the interval to 30 days satisfies the requirement with the least operational overhead because Secrets Manager manages the schedule, invokes the Lambda, and updates the secret version automatically.

Exam trap

SCS-C02 often tests the misconception that you must build custom Lambda/EventBridge automation for rotation, when Secrets Manager's native rotation feature already handles scheduling and versioning.

How to eliminate wrong answers

Option A is wrong because building a custom EventBridge rule plus Lambda duplicates functionality that Secrets Manager already provides natively, adding unnecessary operational overhead. Option B is wrong because a CLI cron job running on an EC2 instance or on-prem host introduces a server to maintain, lacks HA, and does not integrate with Secrets Manager's versioning or staging labels. Option C is wrong because CloudWatch Events (now EventBridge) invoking a Lambda is essentially the same custom approach as option A and ignores the built-in rotation feature.

10
MCQmedium

A company wants to protect data at rest in Amazon S3 using client-side encryption. The application will run on Amazon EC2 instances. Which approach meets these requirements?

A.Use SSE-S3 and rely on S3 to manage keys
B.Enable S3 default encryption on the bucket
C.Use SSE-KMS with a customer managed key
D.Use the AWS Encryption SDK to encrypt data before uploading to S3
AnswerD

The AWS Encryption SDK encrypts objects on the EC2 instance before upload, so plaintext never reaches S3 and keys remain outside AWS's control. This satisfies the stem's client-side encryption requirement for data at rest in S3.

Why this answer

Client-side encryption requires the encryption process to occur on the client side before data is uploaded to S3. The AWS Encryption SDK is designed for this purpose, allowing you to encrypt data locally on the EC2 instance using your own keys, ensuring that S3 never sees the plaintext data. This meets the requirement to protect data at rest with client-side encryption, as the data is encrypted before leaving the application environment.

Exam trap

The trap here is that candidates confuse server-side encryption options (SSE-S3, SSE-KMS) with client-side encryption, assuming that using a customer managed key (SSE-KMS) satisfies client-side requirements when it actually still encrypts data on the server side.

How to eliminate wrong answers

Option A is wrong because SSE-S3 is a server-side encryption method where S3 manages the keys and encrypts data after it is received, not client-side encryption. Option B is wrong because enabling S3 default encryption on the bucket applies server-side encryption (SSE-S3 or SSE-KMS) to objects at the time of upload, not client-side encryption. Option C is wrong because SSE-KMS with a customer managed key is still server-side encryption; the encryption happens on the S3 side after the data is transmitted, not on the client side.

11
MCQeasy

A company wants to protect data in transit between an EC2 instance and an S3 bucket. Which method should be used?

A.Use a VPN connection with IPsec
B.Install an SSL certificate on the EC2 instance
C.Use SSH to transfer files
D.Use HTTPS endpoints for S3 API calls
AnswerD

Using HTTPS endpoints for S3 API calls means every request and response is encrypted with TLS, preventing attackers from reading or tampering with data in transit between an EC2 instance and S3. All AWS SDKs and the AWS CLI are configured to use HTTPS by default when sending S3 operations, and S3's TLS endpoints provide server authentication via AWS-managed certificates. This is the correct, native mechanism to meet the data-in-transit protection requirement for EC2-to-S3 communication.

Why this answer

To protect data in transit between an EC2 instance and an S3 bucket, you must use HTTPS endpoints for S3 API calls, which encrypts traffic using TLS. S3 supports HTTPS natively via its REST API endpoints, and this is the standard method to ensure encryption in transit for S3 access from EC2.

Exam trap

SCS-C02 often tests the confusion between network-layer encryption (VPN/IPsec) and application-layer TLS, leading candidates to choose VPN when the question specifically asks about protecting S3 API traffic.

How to eliminate wrong answers

Option A is wrong because a VPN with IPsec encrypts traffic at the network layer between sites or VPCs, but it does not provide the application-layer TLS encryption required for S3 API calls and is not the recommended method for securing EC2-to-S3 traffic. Option B is wrong because installing an SSL certificate on the EC2 instance secures inbound connections to that instance, not outbound API calls to S3 — the certificate must be on the S3 endpoint side, which AWS already manages. Option C is wrong because SSH is used for remote shell access and SFTP, not for S3 API operations; S3 does not support SSH as a transfer protocol.

12
MCQmedium

A company uses AWS KMS to manage encryption keys for sensitive data stored in S3. The security team wants to ensure that keys are rotated automatically every year. What should they do?

A.Enable automatic key rotation on a customer managed key.
B.Use a custom key store and rotate keys manually.
C.Use a CloudHSM to store keys and rotate them manually.
D.Use an AWS managed key, which rotates automatically every year.
AnswerA

Enabling automatic key rotation on a customer managed key lets AWS KMS rotate the backing key material annually without changing the key ID or ARN, so existing ciphertext and applications continue working. This satisfies the yearly rotation requirement.

Why this answer

Automatic key rotation is a native feature of AWS KMS customer managed keys (CMKs). Enabling it causes KMS to generate new backing key material every year (or a custom period of 90-2560 days) while retaining the same key ID, so existing ciphertext remains decryptable without re-encryption. This satisfies the 'rotate automatically every year' requirement with no manual intervention.

Exam trap

SCS-C02 often tests the distinction between customer managed keys (configurable rotation) and AWS managed keys (automatic but not controllable) — candidates who pick the AWS managed key option miss the governance requirement.

How to eliminate wrong answers

Option B is wrong because a custom key store backed by CloudHSM does not support automatic rotation — rotation must be performed manually, which contradicts the requirement. Option C is wrong for the same reason: CloudHSM-stored keys require manual rotation and add operational overhead. Option D is wrong because AWS managed keys do rotate automatically every year, but the security team cannot control or audit the rotation schedule, and AWS managed keys cannot be used for cross-account access or custom key policies — customer managed keys are the correct choice for a security team that needs governance.

13
MCQeasy

A company wants to protect sensitive data stored in Amazon S3 by encrypting it at rest. Which AWS service can be used to manage the encryption keys?

A.AWS Secrets Manager
B.AWS CloudHSM
C.AWS S3-managed keys (SSE-S3)
D.AWS Key Management Service (AWS KMS)
AnswerD

AWS KMS is a fully managed service for creating and controlling the encryption keys used across AWS services, and it natively integrates with Amazon S3 through SSE-KMS. You can create a customer managed key, define key policies and grants, set automatic annual rotation, and control access via IAM policies and key conditions. With envelope encryption, KMS protects each S3 object with a unique data key that is encrypted by your KMS key, allowing you to centrally manage, monitor, and revoke the master key while still receiving CloudTrail logs for every decrypt operation.

Why this answer

AWS Key Management Service (AWS KMS) is the AWS service designed to create, manage, rotate, and audit encryption keys used to protect data at rest in AWS services including Amazon S3. S3 server-side encryption with AWS KMS keys (SSE-KMS) integrates directly with KMS, giving the company centralized key management, granular IAM policies, key rotation, and CloudTrail audit logs of key usage. This is the correct answer for managing encryption keys for S3 data at rest.

Exam trap

SCS-C02 often tests the distinction between SSE-S3 (AWS-managed keys, no customer control) and SSE-KMS (customer-managed keys via KMS), and candidates must recognize that 'manage the encryption keys' implies KMS, not Secrets Manager or CloudHSM.

How to eliminate wrong answers

Option A is wrong because AWS Secrets Manager is for storing and rotating secrets such as database credentials and API keys, not for managing encryption keys for S3 data at rest. Option B is wrong because AWS CloudHSM is a dedicated hardware security module for customers with strict compliance requirements who need single-tenant key storage; it is overkill and not the standard service for S3 encryption key management. Option C is wrong because SSE-S3 uses S3-managed keys, which means AWS manages the keys entirely and the customer has no control over key management — the question asks which service can be used to manage the encryption keys, implying customer-managed control.

14
MCQmedium

A company runs a web application on Amazon EC2 instances that processes credit card data. The application must store the data in an encrypted format. The security team wants to minimize the performance impact of encryption and offload the encryption operations to a dedicated hardware security module (HSM). Which solution should the architect choose?

A.Use Amazon EBS encryption on the EC2 instance's root volume.
B.Use the Linux dm-crypt utility to encrypt the data at the application level.
C.Use AWS CloudHSM to perform encryption operations from the application.
D.Use AWS KMS with a customer-managed key to encrypt the data in the application.
AnswerC

CloudHSM provides a dedicated HSM, offloading encryption.

Why this answer

AWS CloudHSM provides dedicated hardware security modules that can perform cryptographic operations, including encryption, offloading the work from the application's CPU. It is designed for applications that require dedicated HSM hardware for compliance or performance reasons. Using CloudHSM allows the application to call the HSM for encryption, minimizing performance impact on the EC2 instance.

Exam trap

SCS-C02 often tests the confusion between AWS KMS and CloudHSM, where candidates think KMS provides dedicated HSM offload, but KMS is a multi-tenant service and does not offload encryption operations from the application.

How to eliminate wrong answers

Option A is wrong because EBS encryption encrypts data at rest on the volume but does not offload encryption operations to a dedicated HSM; it uses AWS-managed keys and the encryption is handled by the EC2 instance's CPU. Option B is wrong because dm-crypt is a software-based encryption tool that uses the instance's CPU, not a dedicated HSM. Option D is wrong because AWS KMS is a managed service that uses HSMs internally but does not provide a dedicated HSM for the application to offload encryption; KMS is for key management and encryption of small data, not for bulk encryption offload.

15
MCQmedium

A company is migrating on-premises databases to Amazon RDS for MySQL. The security team requires that data be encrypted at rest and in transit. Which combination of steps should the team take to meet these requirements?

A.Use an RDS proxy with TLS termination and enable encryption at rest.
B.Enable encryption at rest on the RDS instance and set the rds.force_ssl parameter to 1 in the DB parameter group.
C.Enable encryption at rest on the RDS instance and use a client-side encryption library.
D.Enable encryption at rest and configure the security group to allow only HTTPS traffic.
AnswerB

Enabling encryption at rest on the RDS instance protects data files and automated backups using AWS KMS-managed keys, addressing the at-rest requirement. Setting rds.force_ssl=1 in the DB parameter group configures the MySQL/PostgreSQL engine to accept only TLS/SSL-encrypted connections, forcing all clients to negotiate an encrypted transport. Applying this parameter group requires a reboot, and after that every connection—including from read replicas—must use SSL, thereby satisfying both at-rest and in-transit encryption.

Why this answer

Enabling encryption at rest on the RDS instance (which can be done during creation or via a snapshot copy with encryption enabled) and requiring SSL for connections (by setting the rds.force_ssl parameter to 1 in the DB parameter group) ensures data is encrypted both at rest and in transit. Option A is incorrect because an RDS proxy with TLS termination does not enforce encryption for direct connections to the database, and encryption at rest alone does not cover in-transit. Option C is incorrect because using a client-side encryption library is not a standard RDS feature and would require application changes; it does not provide at-rest encryption managed by RDS.

Option D is incorrect because configuring the security group to allow only HTTPS traffic is for HTTP-based services, not for MySQL connections; MySQL uses a different protocol, and HTTPS does not apply to database connections.

16
Multi-Selecthard

Which TWO of the following are valid methods to enforce encryption at rest for an Amazon RDS for PostgreSQL DB instance? (Choose 2.)

Select 2 answers
A.Enable encryption on an existing unencrypted DB instance
B.Restore a DB instance from an encrypted snapshot
C.Take a snapshot of the unencrypted instance and enable encryption on the snapshot
D.Create an encrypted read replica and promote it
E.Create a new encrypted DB instance from the start
AnswersB, E

Restoring a DB instance from an encrypted snapshot creates a new instance that is automatically encrypted using the KMS key that encrypted the snapshot. This process preserves the data while transferring encryption settings to the restored instance, making it a valid method for both new deployments and migrations from existing encrypted data. You may optionally choose a different customer-managed key during the restore, but encryption is guaranteed to be enabled.

Why this answer

Option B is correct because restoring from an encrypted snapshot is a supported way to obtain an encrypted DB instance: you can encrypt a snapshot copy (or use an already encrypted snapshot) and restore it, producing a DB instance with encryption at rest enabled via KMS. Option E is correct because encryption at rest for Amazon RDS for PostgreSQL must be specified at creation time; when you create a new DB instance you can enable encryption, and the underlying storage, automated backups, read replicas, and snapshots are then encrypted with the selected AWS KMS key. Option A is not valid because you cannot enable encryption on an existing unencrypted RDS DB instance in place; you must create an encrypted copy/restore.

Option C is not valid because you cannot take a snapshot of an unencrypted instance and simply 'enable encryption on the snapshot' in place; you must copy the snapshot with encryption enabled. Option D is not valid because an encrypted read replica cannot be created from an unencrypted source instance, so this method cannot enforce encryption at rest for the original unencrypted DB instance.

Exam trap

The trap is thinking you can enable encryption on an existing instance or snapshot; encryption must be set at creation or via an encrypted snapshot copy.

17
Multi-Selecteasy

Which TWO methods can be used to encrypt data at rest in Amazon S3? (Choose 2.)

Select 2 answers
A.Set a bucket policy that denies uploads without encryption.
B.Use SSE-S3 to have Amazon S3 manage the encryption keys.
C.Enable encryption in transit using HTTPS.
D.Enable MFA Delete on the S3 bucket.
E.Encrypt the objects client-side before uploading to S3.
AnswersB, E

SSE-S3 (Server-Side Encryption with Amazon S3-managed keys) encrypts each object using AES-256 with a unique key, and that key is then protected by a regularly rotated master key owned by S3. When enabled, S3 automatically encrypts data as it writes to disk and decrypts it transparently on retrieval, with no additional key management burden for the customer. This is a fully managed, low-overhead method for encrypting data at rest in S3.

Why this answer

Option B is correct because SSE-S3 (server-side encryption with Amazon S3-managed keys, AES-256) encrypts objects at rest, with AWS fully managing the key material and rotation. Option E is correct because client-side encryption means data is encrypted before it leaves the client and is stored in S3 already encrypted, so the objects are protected at rest. Option A is not a valid answer because a bucket policy denying unencrypted uploads only enforces that encryption is used; it does not itself encrypt data.

Option C is incorrect because HTTPS/TLS provides encryption in transit, not at rest. Option D is incorrect because MFA Delete only adds an authentication requirement for deleting objects or changing versioning state; it does not encrypt data.

Exam trap

The trap here is conflating encryption in transit (HTTPS) or access controls (bucket policies, MFA Delete) with encryption at rest — candidates must recognize that only SSE variants and client-side encryption actually encrypt stored data.

18
MCQeasy

A company wants to encrypt data at rest in Amazon S3 using server-side encryption with Amazon S3-managed keys (SSE-S3). What is the minimum permission required for an IAM user to upload an object that will be encrypted with SSE-S3?

A.s3:PutObjectAcl
B.kms:Decrypt
C.s3:PutObject
D.kms:GenerateDataKey
AnswerC

This is the correct permission needed to upload any object to S3, regardless of whether server-side encryption is enabled. When using SSE-S3, S3 automatically encrypts the object with a unique key that is itself wrapped by a master key managed by S3, all happening transparently in the service. The caller only needs the standard s3:PutObject permission; no separate KMS or encryption-specific permissions are required for the upload to succeed with encryption.

Why this answer

For SSE-S3, Amazon S3 manages the encryption keys entirely, so the IAM user does not need any AWS KMS permissions. The only permission required to upload an object with SSE-S3 is s3:PutObject, which allows the upload operation. S3 automatically encrypts the object with an S3-managed key when the request specifies SSE-S3 or when default encryption is enabled.

Exam trap

SCS-C02 often tests the confusion between SSE-S3 and SSE-KMS permission requirements, tempting candidates to select KMS permissions (kms:GenerateDataKey, kms:Decrypt) for SSE-S3 when S3 manages keys internally and no KMS permissions are needed.

How to eliminate wrong answers

Option A is wrong because s3:PutObjectAcl controls the ability to set an object's ACL, which is unrelated to encryption and not required for SSE-S3 uploads. Option B is wrong because kms:Decrypt is a KMS permission needed when using SSE-KMS to decrypt data keys, not for SSE-S3 where S3 manages keys internally. Option D is wrong because kms:GenerateDataKey is a KMS permission required for SSE-KMS to generate data keys, not for SSE-S3, which uses S3-managed keys and does not call KMS.

19
MCQmedium

A security engineer is troubleshooting an issue where an Amazon RDS for MySQL DB instance encrypted at rest with AWS KMS is failing to launch. The error message indicates a KMS access issue. Which IAM role or policy is most likely missing?

A.The RDS subnet group is in a private subnet without a NAT gateway
B.The DB instance's security group does not allow outbound traffic to KMS
C.The KMS key policy does not grant access to the root account
D.The AWSServiceRoleForRDS service-linked role is missing
AnswerD

The AWSServiceRoleForRDS service-linked role is a predefined IAM role that gives RDS the ability to call AWS services, including KMS, on your behalf for tasks such as encrypting and decrypting database storage. When this role is missing, RDS cannot assume it to perform kms:Encrypt, kms:Decrypt, or kms:GenerateDataKey operations, causing failures when you create, modify, or start an encrypted instance. This is the root cause in this scenario; you can verify or create the role with the AWS CLI command aws iam create-service-linked-role --aws-service-name rds.amazonaws.com.

Why this answer

The AWSServiceRoleForRDS service-linked role is required for RDS to call AWS KMS on your behalf to manage encryption keys for encrypted DB instances. If this role is missing, RDS cannot obtain the necessary permissions to decrypt the KMS key during instance launch, resulting in a KMS access error. This role is automatically created the first time you create an RDS resource, but if it was deleted or not present, you must recreate it to resolve the issue.

Exam trap

The trap here is that candidates often focus on KMS key policies or network configurations, but the real issue is the missing service-linked role that grants RDS the service-level permissions to interact with KMS, which is a common oversight in encrypted RDS troubleshooting scenarios.

How to eliminate wrong answers

Option A is wrong because the subnet group configuration (private subnet without NAT gateway) affects network connectivity, not KMS permissions; RDS can launch in a private subnet without a NAT gateway as long as it has a VPC endpoint or proper routing to KMS. Option B is wrong because security groups control network traffic at the instance level, but KMS access is managed via IAM policies and key policies, not outbound traffic rules; RDS uses AWS KMS over HTTPS, which does not require a specific security group rule for outbound traffic to KMS. Option C is wrong because the KMS key policy granting access to the root account is a default best practice, but the missing element is the service-linked role that allows RDS to assume the necessary permissions; the root account already has full access by default.

20
MCQeasy

A company wants to ensure that data stored in Amazon EBS volumes is encrypted at rest. What is the easiest way to achieve this?

A.Use AWS KMS to rotate the EBS encryption key
B.Use a script to encrypt each volume after creation
C.Enable EBS encryption by default in the AWS Region
D.Use application-level encryption
AnswerC

Enabling EBS encryption by default in the Region is the easiest and most reliable method because it instructs the EC2 service to always encrypt newly created volumes and snapshots at the storage layer. When enabled, every new EBS volume and every new snapshot is encrypted with your default AWS KMS key (either the aws/ebs managed key or a customer-managed key you designate). This setting applies to all volumes created in that Region, including root volumes launched from unencrypted AMIs, without requiring you to modify applications or remember to check an encryption box.

Why this answer

Enabling EBS encryption by default in the AWS Region automatically encrypts all new EBS volumes and snapshots with no additional effort. Option A is incorrect: KMS key rotation does not enable encryption; it rotates the key used for encryption. Option B is incorrect: while you can encrypt individual volumes after creation, the easiest method is to enable default encryption.

Option D is incorrect: application-level encryption is not needed for EBS volumes and is more complex to implement.

21
MCQmedium

A security engineer needs to protect sensitive data stored in an Amazon S3 bucket. The data must be encrypted at rest using a customer managed key in AWS KMS, and the engineer wants to ensure that all requests to upload objects without encryption are automatically denied. The bucket is in account 111122223333. Which S3 bucket policy statement should the engineer use?

A.A statement that denies s3:PutObject if the request includes the s3:x-amz-server-side-encryption header with value aws:kms.
B.A statement that denies s3:PutObject if the request lacks the s3:x-amz-server-side-encryption header with value aws:kms.
C.A statement that denies s3:PutObject if the request does not include the s3:x-amz-server-side-encryption header with value AES256.
D.A statement that allows s3:PutObject only if the request includes the s3:x-amz-server-side-encryption header with value AES256.
AnswerB

This policy uses a Deny effect with a condition that checks for the presence and value of the s3:x-amz-server-side-encryption header. If a PutObject request does not include the header with aws:kms, the request is denied. This enforces encryption with SSE-KMS for all uploads. It is the standard way to require a specific encryption method for objects uploaded to an S3 bucket.

Why this answer

To enforce that all objects uploaded to an S3 bucket are encrypted with SSE-KMS, the bucket policy must include a Deny statement that blocks PutObject requests when the s3:x-amz-server-side-encryption header is missing or not set to aws:kms. This ensures that any upload without the required encryption header is rejected. Allow statements alone do not prevent non-compliant uploads, and conditions specifying AES256 enforce SSE-S3, not SSE-KMS.

Exam trap

The trap here is using an Allow statement instead of a Deny statement, or confusing the header value for SSE-S3 (AES256) with SSE-KMS (aws:kms).

22
MCQeasy

A security engineer is investigating a potential data breach and finds this CloudTrail log entry. What does this entry indicate?

A.A user encrypted data using a KMS key
B.A user decrypted data using a KMS key
C.An anonymous user accessed the KMS key
D.The KMS key was deleted
AnswerB

The wrong options are eliminated because this is a Decrypt event: a user invoked the KMS Decrypt API to reveal plaintext from previously encrypted data. In an investigation, this event is significant because it shows the KMS key was used to turn ciphertext into plaintext, which is how an attacker or insider would access data after exfiltrating it. Therefore, this interpretation correctly matches the CloudTrail record and indicates a potential data disclosure.

Why this answer

The CloudTrail entry shows a Decrypt API call against a KMS key, which indicates a principal used the key to decrypt ciphertext. This is the standard CloudTrail event emitted when KMS performs a cryptographic decryption operation.

Exam trap

The trap here is that candidates see a KMS-related CloudTrail entry and assume encryption or key deletion, when the specific eventName (Decrypt) is the decisive detail that must be read carefully.

How to eliminate wrong answers

Option A is wrong because encryption would appear as an Encrypt event, not Decrypt. Option C is wrong because CloudTrail records the authenticated principal's ARN; anonymous access to KMS is not possible since KMS requires IAM authentication. Option D is wrong because key deletion appears as ScheduleKeyDeletion or DisableKey, not Decrypt.

23
Multi-Selectmedium

A company is designing a data protection strategy for its Amazon S3 bucket that stores sensitive documents. The security team requires that all data be encrypted in transit and at rest, and that any accidental deletion of objects can be reversed within 30 days. Additionally, the company must be able to audit all access attempts to the bucket, including failed attempts. Which TWO actions should the company take to meet these requirements? (Choose two.)

Select 2 answers
A.Enable default encryption on the bucket using SSE-S3.
B.Enable AWS CloudTrail with data events for S3.
C.Enable S3 Versioning on the bucket.
D.Enable S3 server access logs and send them to a separate bucket.
E.Enable MFA Delete on the bucket.
AnswersB, C

Enabling CloudTrail with data events for an S3 bucket records object-level operations such as GetObject, PutObject, DeleteObject, and HeadObject, capturing the IAM principal, source IP, and whether the request succeeded or failed. This creates an authoritative, queryable audit trail that can be searched in CloudTrail Lake or Athena and is essential for incident investigation, compliance reporting, and detecting compromised credentials. Unlike server access logs, CloudTrail data events reliably include failed attempts.

Why this answer

AWS CloudTrail with data events for S3 is correct because it captures all S3 API calls, including GetObject, PutObject, and DeleteObject, and records both successful and failed access attempts. This meets the auditing requirement for all access attempts, including failed ones, as CloudTrail logs the request details, error codes, and source IP addresses.

Exam trap

The trap here is that candidates often confuse S3 server access logs (which log successful requests only) with CloudTrail data events (which log all API calls, including failures), leading them to select Option D instead of Option B.

24
Multi-Selectmedium

A company wants to protect sensitive data stored in S3 from being accessed by unauthorized users. Which TWO actions should be taken? (Choose two.)

Select 2 answers
A.Use IAM policies to restrict access to the bucket.
B.Enable S3 Versioning.
C.Enable default encryption on all S3 buckets.
D.Enable S3 Block Public Access at the account level.
E.Enable MFA Delete on the bucket.
AnswersA, D

IAM policies are the primary identity-based access control in AWS. They allow you to grant specific principals, such as IAM users or roles, explicit Allow or Deny permissions for S3 actions on a given bucket and its objects. When combined with resource-based bucket policies, IAM enables fine-grained authorization, such as requiring s3:GetObject only for certain prefixes, which directly prevents unauthorized access to sensitive data.

Why this answer

Option A is correct because IAM policies define which principals (users, roles, groups) can perform which S3 actions (such as s3:GetObject or s3:PutObject) on specific bucket or object ARNs, directly controlling authorized access to sensitive data. Option D is correct because enabling S3 Block Public Access at the account level applies account-wide safeguards that reject bucket policies or ACLs granting public access, preventing accidental exposure of sensitive objects to anonymous users. Option B is not correct because S3 Versioning only preserves multiple object versions for recovery and does not by itself prevent unauthorized access.

Option C is not correct because default encryption protects data at rest but does not stop an authorized-but-malicious or improperly permissioned principal from reading the data. Option E is not correct because MFA Delete only requires multi-factor authentication for permanently deleting object versions or changing versioning state, which is a deletion control rather than an access control.

Exam trap

The trap is confusing encryption with access control; candidates may think enabling default encryption prevents unauthorized access, but it only protects data at rest, not from authorized users with excessive permissions.

25
MCQhard

Refer to the exhibit. A user named John encrypts a file using the AWS CLI. John then tries to decrypt the file but receives an AccessDenied error. John has full administrator permissions in IAM. What is the most likely cause?

A.The ciphertext blob is malformed because it was not base64-decoded before decryption.
B.John's IAM policy denies the kms:Decrypt action.
C.The KMS key policy does not grant John the kms:Decrypt permission.
D.The key ID used for encryption is different from the key used for decryption.
AnswerC

A KMS key policy is a resource-based policy that defines which principals may use that key, and it must explicitly grant the decrypt permission to John. Even with admin IAM permissions, if John isn't listed as a principal in the key policy, AWS KMS denies the decryption call with AccessDenied. The correction is to add John as a principal with kms:Decrypt action in the key policy or configure the key policy to allow IAM policies, then keep his IAM permission.

Why this answer

The most likely cause is that the KMS key policy does not grant John the kms:Decrypt permission. Even though John has full administrator permissions in IAM, KMS key policies are resource-based policies that must explicitly allow the principal to use the key. If the key policy does not grant John decrypt permissions, access is denied.

Exam trap

SCS-C02 often tests the interaction between IAM policies and KMS key policies; candidates may assume that IAM admin permissions are sufficient for KMS operations, ignoring key policy requirements.

How to eliminate wrong answers

Option A is wrong because the AWS CLI automatically handles base64 encoding/decoding for ciphertext blobs; a malformed blob would typically result in a different error. Option B is wrong because John has full administrator permissions, so an IAM policy deny is unlikely unless there is an explicit deny, but the question states he has full admin. Option D is wrong because using a different key ID would result in a different error, such as InvalidCiphertextException, not AccessDenied.

26
MCQeasy

An application running on Amazon EC2 needs to access an S3 bucket containing sensitive data. The security team wants to avoid storing long-term AWS credentials on the instance. How should the EC2 instance be configured to access S3 securely?

A.Assign an IAM role with S3 permissions to the EC2 instance via an instance profile.
B.Store IAM user access keys in the instance's user data.
C.Attach a KMS key policy that allows the instance to decrypt S3 objects.
D.Generate S3 pre-signed URLs for all objects the instance needs to access.
AnswerA

An instance profile delivers temporary, automatically rotated credentials to the EC2 instance through the instance metadata service, so no long-term access keys are stored on disk. The attached IAM role scopes S3 permissions precisely, satisfying the requirement to avoid embedded credentials.

Why this answer

Assigning an IAM role to an EC2 instance via an instance profile is the AWS-recommended way to grant AWS service permissions without embedding long-term credentials. The instance profile delivers temporary, automatically rotated credentials through the EC2 Instance Metadata Service (IMDS) at 169.254.169.254, which the SDK/CLI retrieves transparently. This satisfies the security team's requirement to avoid storing long-term AWS credentials on the instance while still allowing least-privilege S3 access.

Exam trap

SCS-C02 often tests the misconception that a KMS key policy or pre-signed URLs can substitute for IAM role-based instance permissions, when in fact only an instance profile grants the instance itself AWS API authorization.

How to eliminate wrong answers

Option B is wrong because storing IAM user access keys in user data embeds long-term credentials in the instance, which are visible to anyone with metadata/console access and violate the no-long-term-credentials requirement. Option C is wrong because a KMS key policy only governs who may use a KMS key for encryption/decryption — it does not grant S3 API permissions and cannot by itself authorize the instance to call S3. Option D is wrong because pre-signed URLs are time-limited, per-object, and typically generated by an already-authorized principal; they are not a scalable or secure mechanism for an application to continuously access a bucket.

27
MCQmedium

A company uses AWS KMS to encrypt data in Amazon RDS. They need to ensure that the key material is automatically rotated every year. Which key type should they use?

A.Custom key store
B.Customer managed key
C.AWS owned key
D.AWS managed key
AnswerD

AWS managed keys are KMS keys created automatically when a service first needs encryption, and Amazon RDS's AWS managed key (alias aws/rds) has automatic rotation enabled by default, rotating the backing key material every year. Because the key is managed in the AWS account's service space, you cannot disable rotation, which neatly matches a requirement for guaranteed automatic rotation without any administrative action.

Why this answer

AWS managed keys (D) are automatically rotated every year by AWS without any action required from the customer. For Amazon RDS encryption using AWS KMS, the default key (aws/rds) is an AWS managed key that supports automatic annual rotation, meeting the requirement exactly. Customer managed keys (B) also support automatic rotation, but the question specifies 'every year' and AWS managed keys are the simplest choice that satisfies this, as they are automatically rotated annually by default.

Exam trap

The trap here is that candidates often confuse 'AWS managed key' with 'customer managed key' because both can be rotated, but the question tests whether you know that AWS managed keys are the default, automatically rotated keys used by services like RDS, and that customer managed keys require manual configuration for rotation.

How to eliminate wrong answers

Option A is wrong because a custom key store uses a CloudHSM cluster to store key material, and automatic key rotation is not supported for keys in a custom key store; rotation must be manually managed. Option B is wrong because while customer managed keys can be configured for automatic annual rotation, the question does not specify a need for customer control over the key, and AWS managed keys are the default, simpler option that also rotates annually. Option C is wrong because AWS owned keys are not visible to customers and are used by AWS services internally; they cannot be selected or managed by the customer for RDS encryption, and their rotation policy is not under customer control.

28
MCQmedium

A security engineer needs to encrypt a 10 GB file before uploading it to Amazon S3. The encryption must use a customer managed key in AWS KMS, and the engineer wants to minimize the amount of data sent to KMS for encryption. Which approach should the engineer use?

A.Upload the file to S3 using SSE-KMS with the customer managed key, which encrypts the entire file with KMS.
B.Use the KMS Encrypt API directly to encrypt the entire file with the customer managed key, then upload the encrypted file to S3.
C.Use the AWS Encryption SDK with a customer managed KMS key to encrypt the file locally, then upload the encrypted file to S3.
D.Use S3 client-side encryption with a customer provided key (SSE-C) and store the key in AWS KMS.
AnswerC

The AWS Encryption SDK uses envelope encryption: it generates a data key, encrypts the file with that data key, and encrypts the data key with the KMS customer managed key. Only the small data key is sent to KMS, minimizing data transfer. The encrypted file and encrypted data key are stored together. This meets the requirement to minimize data sent to KMS.

Why this answer

The AWS Encryption SDK implements envelope encryption locally, using a KMS customer managed key only to encrypt a data key. This minimizes data sent to KMS because only the small data key is transmitted. The encrypted file is then uploaded to S3.

This meets the requirements for local encryption and efficient KMS usage.

Exam trap

The trap here is assuming that KMS can directly encrypt large files, when in fact the Encrypt API has a 4 KB limit, necessitating envelope encryption.

29
MCQmedium

A company uses S3 to store sensitive customer data. They want to ensure that all S3 buckets have encryption enabled at rest. Which S3 feature should be used to automatically enforce encryption on all newly created objects?

A.S3 Block Public Access
B.S3 Object Lock
C.S3 Bucket Policy with a condition requiring server-side encryption
D.S3 Inventory
AnswerC

A bucket policy can enforce server-side encryption by using the request header condition keys `s3:x-amz-server-side-encryption` and `s3:x-amz-server-side-encryption-aws-kms-key-id`. For instance, a `Deny` statement with `StringNotEquals` on `s3:x-amz-server-side-encryption` for `aws:kms`, combined with a `Null` condition that denies uploads where the header is absent, will reject every `PutObject` and `InitiateMultipartUpload` that does not specify SSE-KMS. This is a direct, request-time enforcement mechanism.

Why this answer

An S3 bucket policy with a condition requiring server-side encryption (e.g., 's3:x-amz-server-side-encryption': 'aws:kms' or 'AES256') can deny any PutObject request that does not include the encryption header, thereby automatically enforcing encryption on all newly created objects. Option A is incorrect because S3 Block Public Access controls public access, not encryption. Option B is incorrect because S3 Object Lock is for write-once-read-many (WORM) retention, not encryption enforcement.

Option D is incorrect because S3 Inventory provides a list of objects and their metadata but does not enforce encryption.

30
MCQmedium

A company is designing a data protection strategy for its Amazon RDS for MySQL database. The database contains sensitive data that must be encrypted at rest. The company also needs to manage the encryption keys using its own HSM. Which solution should be used?

A.Use client-side encryption with a key from CloudHSM
B.Use AWS CloudHSM to generate a key and import it into RDS
C.Enable encryption at rest using the default AWS KMS key
D.Use AWS KMS with a custom key store backed by AWS CloudHSM
AnswerD

This is the correct approach because AWS KMS custom key stores let you create a CMK whose key material is stored in a CloudHSM cluster that you fully control. When you enable RDS encryption at rest, RDS uses this CMK to encrypt the storage, and the key material never leaves your HSM. This gives you the dual benefit of RDS-native transparent encryption and the cryptographic ownership of an HSM, satisfying the data protection strategy.

Why this answer

To encrypt an Amazon RDS for MySQL database at rest while managing keys in a customer-owned HSM, you must use AWS KMS with a custom key store backed by AWS CloudHSM. This allows you to use keys from your own CloudHSM cluster for RDS encryption. Option D is correct.

Option A is incorrect because client-side encryption is not for at-rest encryption of the RDS instance itself. Option B is incorrect because you cannot directly import keys from CloudHSM into RDS; the integration is through KMS custom key store. Option C is incorrect because the default AWS KMS key does not allow you to manage the key in your own HSM.

31
MCQhard

A company uses AWS KMS to encrypt data in Amazon S3. The security team receives an alert that an IAM user is attempting to decrypt data using a key that they do not have access to. Which AWS service can be used to monitor and alert on such unauthorized KMS API calls?

A.Amazon GuardDuty
B.AWS Config
C.AWS CloudTrail with CloudWatch Alarms
D.Amazon Inspector
AnswerC

AWS CloudTrail captures every KMS API request as a management event, including kms:Encrypt, kms:Decrypt, and kms:ScheduleKeyDeletion, and delivers those logs to an S3 bucket. You can then define a CloudWatch Logs metric filter on the JSON field of the CloudTrail event to match a specific KMS action, and attach a CloudWatch Alarm to that metric to trigger an SNS notification. This combination provides the required trackable, alertable audit trail for KMS API calls made when S3 encrypts objects using customer-managed KMS keys.

Why this answer

AWS CloudTrail logs all KMS API calls, and CloudWatch Alarms can be configured to trigger on specific unauthorized API calls, such as Decrypt attempts with a key the user does not have access to. Option A is incorrect because Amazon GuardDuty is a threat detection service that focuses on identifying malicious activity, but it does not provide detailed monitoring of specific KMS API calls. Option B is incorrect because AWS Config evaluates resource configurations and compliance, not API calls.

Option D is incorrect because Amazon Inspector is a vulnerability assessment service for EC2 instances and does not monitor API calls.

32
MCQhard

A company stores data in Amazon S3 and uses AWS KMS with Customer Master Keys (CMKs) for encryption. The security team wants to audit when the CMK is used to decrypt data. Which of the following will provide this information?

A.AWS Config
B.Amazon CloudWatch Logs
C.AWS CloudTrail
D.S3 server access logs
AnswerC

AWS CloudTrail is the authoritative source for KMS API activity because it records KMS calls as data events, including Decrypt, Encrypt, GenerateDataKey, and ReEncrypt. Each KMS data event in CloudTrail includes the key ID, whether decryption succeeded, the principal and ARN of the caller, the source IP, and the request timestamp. By enabling CloudTrail data events for a customer-managed KMS key, you get a complete audit trail that you can search in Athena or deliver to CloudWatch Logs for alerting.

Why this answer

AWS CloudTrail logs all KMS Decrypt API calls, which is exactly what is needed to audit CMK decryption. Option A (AWS Config) records configuration changes, not API calls. Option B (Amazon CloudWatch Logs) can store logs but does not generate the KMS decrypt logs itself; CloudTrail generates them.

Option D (S3 server access logs) record requests to S3 objects, not the KMS decryption calls that happen when accessing encrypted objects.

33
Multi-Selecthard

Which THREE of the following are required to use client-side encryption with Amazon S3 using AWS KMS? (Choose three.)

Select 3 answers
A.An S3 bucket policy that forces encryption.
B.The encrypted data key is stored as metadata with the S3 object.
C.A KMS key policy that allows the S3 service to decrypt.
D.Permissions for the IAM user or role to call kms:GenerateDataKey.
E.The AWS SDK Encryption Client library.
AnswersB, D, E

In the client-side encryption envelope scheme, the SDK creates a one-time data key, encrypts the object with it, then wraps that data key with a KMS customer master key. The resulting encrypted data key is stored in the S3 object's metadata, for example the x-amz-meta-x-amz-key-v2 attributes, so a decrypter can later retrieve it and unwrap it to get the plaintext data key. Without this metadata, the ciphertext cannot be decrypted, so this storage step is a required part of client-side encryption.

Why this answer

Option B is correct because with client-side encryption using the AWS SDK Encryption Client, the SDK generates a data key, encrypts the object locally, and stores the encrypted (wrapped) data key as metadata alongside the S3 object so it can be retrieved and unwrapped later. Option D is correct because the caller must have IAM permissions to invoke kms:GenerateDataKey (and typically kms:Decrypt) so the SDK can obtain a plaintext data key and a wrapped copy from AWS KMS. Option E is correct because client-side encryption is performed by the AWS SDK Encryption Client library (e.g., AmazonS3EncryptionClient), which handles key generation, local encryption, and metadata storage; S3 itself never sees plaintext.

Option A is not required because a bucket policy forcing encryption governs server-side encryption at the S3 service level and is irrelevant to client-side encryption, which happens before data reaches S3. Option C is not required because the KMS key policy must grant the calling IAM principal (user or role) access to the key, not the S3 service, since S3 is not involved in the KMS operations for client-side encryption.

Exam trap

The trap is confusing client-side encryption with server-side encryption (SSE-KMS) — options about bucket policies and S3 service decrypt permissions belong to SSE, not client-side encryption.

34
MCQmedium

A company wants to protect sensitive data stored in Amazon S3 by enforcing encryption in transit. Which policy should be used to deny requests that do not use HTTPS?

A.{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*", "Condition": {"Bool": {"aws:SecureTransport": "true"}}}
B.{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*", "Condition": {"Bool": {"aws:SecureTransport": "false"}}}
C.{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*", "Condition": {"Null": {"s3:x-amz-server-side-encryption": "true"}}}
D.{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*"}
AnswerB

This policy correctly denies S3 actions when aws:SecureTransport is false, meaning it blocks all HTTP requests that do not use TLS. The aws:SecureTransport key is true only for requests made over HTTPS, so this conditional deny rejects any insecure request while allowing encrypted traffic. This is the AWS-recommended bucket policy pattern for enforcing encryption in transit and satisfies the requirement.

Why this answer

It uses the aws:SecureTransport condition set to 'false' to deny requests that are not using HTTPS. Option A is incorrect because it denies requests when SecureTransport is 'true', meaning it would block legitimate HTTPS traffic. Option C is incorrect because it checks for the presence of the s3:x-amz-server-side-encryption header, which relates to encryption at rest, not encryption in transit.

Option D is incorrect because it denies all requests unconditionally, which would block all traffic, including HTTPS.

35
MCQhard

A company stores sensitive customer data in Amazon S3. The security team has enabled default encryption with SSE-S3 on the bucket. The compliance team requires that all access to the bucket be logged and that any unauthorized access attempts be detected in real time. The company has AWS CloudTrail enabled. Which additional steps should the security team take to meet the compliance requirements?

A.Enable S3 server access logs and enable Amazon GuardDuty with S3 protection
B.Enable AWS Config rules to detect unauthorized access
C.Enable CloudTrail data events for the S3 bucket and use Amazon Detective
D.Enable VPC Flow Logs and use Amazon Athena to analyze logs
AnswerA

S3 server access logs capture every request made to the bucket, including requester IP, IAM role/user, action, and HTTP status, providing a detailed audit trail for forensic analysis. Amazon GuardDuty's S3 protection continuously monitors object-level operations and uses threat intelligence and anomaly detection to flag suspicious patterns, such as mass downloads or access from unusual geographies, in near-real time. Together they deliver both historical evidence and proactive alerting, making this the only option that addresses both detection and investigation of unauthorized access.

Why this answer

Enabling S3 server access logs captures all requests to the bucket, satisfying the logging requirement, and Amazon GuardDuty with S3 protection can detect suspicious activity in real time, meeting the requirement for real-time detection of unauthorized access. Option B is incorrect because AWS Config rules monitor configuration changes, not real-time threat detection. Option C is incorrect because CloudTrail data events can log S3 operations, but Amazon Detective is for post-incident analysis, not real-time detection.

Option D is incorrect because VPC Flow Logs log network traffic, not S3 access, and Amazon Athena is a query service, not a real-time detection tool.

36
MCQhard

A company uses AWS CloudHSM to generate and store encryption keys for a custom database. The security team needs to back up the keys to another AWS Region for disaster recovery. What is the most secure and efficient way to achieve this?

A.Create a backup of the source CloudHSM cluster and copy the backup to the destination Region.
B.Export the keys from the source CloudHSM cluster and import them into a destination cluster in the other Region.
C.Enable cross-Region replication on the CloudHSM cluster.
D.Use the key_mgmt_util command-line tool to copy the keys to an on-premises HSM, then upload to the destination Region.
AnswerA

AWS CloudHSM supports taking point-in-time backups of an entire cluster, and those backups can be copied to other regions using the CopyBackupToRegion API or the console. After copying, you restore the backup in the destination region to create a new cluster that contains all original keys, HSMs, and settings. This preserves FIPS 140-2 validated protection because key material never leaves the HSM boundary, and it is the officially supported method for cross-region disaster recovery.

Why this answer

AWS CloudHSM allows you to create a backup of a cluster and copy that backup to another region using the AWS CLI or console. This is the most secure method as it avoids exporting keys in plaintext. Option B is incorrect because CloudHSM does not support exporting keys directly; you must use backups.

Option C is incorrect because CloudHSM does not have a cross-region replication feature for clusters. Option D is incorrect because copying keys via an on-premises HSM is unnecessary and less secure than using CloudHSM's built-in backup copy functionality.

37
MCQmedium

A company stores sensitive customer data in Amazon S3. To comply with data protection regulations, they need to automatically prevent any new objects from being made publicly accessible. Which S3 feature should they configure?

A.Enable S3 Block Public Access at the account level.
B.Configure a bucket policy that denies s3:PutObject with a condition for public access.
C.Use S3 default encryption with SSE-S3.
D.Enable S3 Object Lock in governance mode.
AnswerA

Account-level S3 Block Public Access is a set of controls (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets) that act as a centralized guardrail across every bucket in the AWS account. When enabled, it overrides any bucket policy, owner policy, or object ACL that would grant public access, and it blocks both existing public grants and future attempts to make objects or buckets public. This is the most comprehensive control because it applies even if a developer mistakenly attaches a permissive bucket policy or uploads an object with a public-read ACL.

Why this answer

S3 Block Public Access at the account level applies a blanket deny on any policy or ACL that would make an object or bucket public, and it overrides bucket policies and ACLs. Enabling it at the account level ensures all current and future buckets in the account are protected from accidental public exposure. This is the AWS-recommended preventive control for data protection compliance.

Exam trap

SCS-C02 often tests the misconception that encryption (SSE-S3) or Object Lock provides access control — candidates confuse confidentiality-at-rest with public-access prevention, when only Block Public Access directly blocks public exposure.

How to eliminate wrong answers

Option B is wrong because a bucket policy denying s3:PutObject with a public-access condition is difficult to express correctly — S3 PutObject requests do not carry a reliable 'public' flag, and ACLs/policies set after upload could still expose objects; it is not a preventive account-wide control. Option C is wrong because SSE-S3 provides encryption at rest only; it has no relationship to public accessibility and does not prevent objects from being made public. Option D is wrong because S3 Object Lock (governance mode) prevents deletion or overwrite of object versions for a retention period — it addresses immutability/WORM compliance, not public access prevention.

38
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The application uses an Amazon RDS for MySQL database. The security team requires that all data in transit between the EC2 instances and the database be encrypted. The database is in a private subnet. The EC2 instances are in a public subnet. The security team also wants to minimize latency. What should be done to meet these requirements?

A.Use AWS Certificate Manager to issue a certificate for the RDS endpoint
B.Set up a VPN connection between the EC2 instances and the RDS instance using an IPsec VPN
C.Place the EC2 instances and RDS in the same subnet and use a NAT gateway
D.Enable SSL/TLS on the RDS instance and configure the application to use encrypted connections
AnswerD

Enabling SSL/TLS on the RDS instance forces the database server to accept only encrypted connections, typically by setting the force_ssl parameter (for PostgreSQL) or the SSL/TLS requirement (for MySQL) in the DB parameter group. The application must then connect using TLS with the RDS-generated CA certificate in its trust store, and it should enforce certificate verification to prevent man-in-the-middle attacks. This encrypts all data in transit between the EC2 instances and the RDS endpoint, satisfying the confidentiality requirement with minimal latency overhead and without needing extra networking equipment.

Why this answer

In a typical AWS environment, data in transit between an application and an RDS database can be encrypted using SSL/TLS. RDS for MySQL supports SSL/TLS connections. To meet the requirement, enable SSL/TLS on the RDS instance by downloading the certificate bundle and configuring the DB instance to require encrypted connections.

Then, configure the application to use SSL/TLS when connecting to the database. This approach encrypts data in transit with minimal overhead compared to a VPN, which can introduce latency. Option A (using AWS Certificate Manager for the RDS endpoint) is incorrect because ACM is typically used for load balancers and CloudFront, not for direct database connections.

While ACM can provide certificates for applications, RDS itself uses its own certificate authority for SSL/TLS. Option B (setting up an IPsec VPN) is unnecessary and adds complexity and latency without providing encryption specific to the database connection; SSL/TLS already meets the requirement. Option C (placing instances in the same subnet and using a NAT gateway) does not encrypt data in transit and increases latency via NAT gateway.

39
MCQeasy

Refer to the exhibit. A security engineer reviews the bucket policy for an S3 bucket. The engineer attempts to upload an object to the bucket using the AWS CLI without the --ssl flag (HTTP). What is the outcome?

A.The upload succeeds because the policy allows all actions.
B.The upload fails because the policy denies requests that are not using HTTPS.
C.The upload succeeds because the bucket has default encryption enabled.
D.The upload fails because the policy denies s3:PutObject only.
AnswerB

The bucket policy contains a Deny statement targeting all S3 actions and keyed on the Bool condition aws:SecureTransport=false. Requests made with HTTP set this key to false, so the condition evaluates true, the Deny is applied, and the PutObject upload is rejected. Only HTTPS requests would have SecureTransport=true and therefore would not match this particular Deny; however, an explicit Allow statement is still required to authorize the request.

Why this answer

The bucket policy includes a condition that explicitly denies all s3: actions (including s3:PutObject) when the request does not use HTTPS (SecureTransport is false). Since the engineer uses HTTP (no --ssl flag), the condition is met, and the upload is denied. Option A is incorrect because the policy does not allow all actions; it includes a conditional deny.

Option C is incorrect because default encryption does not override the explicit deny in the policy. Option D is incorrect because the policy denies all s3 actions, not just s3:PutObject.

40
MCQmedium

A company uses AWS KMS with a custom key store backed by AWS CloudHSM. The security team wants to ensure that the key material never leaves the HSM and that all cryptographic operations are performed within the HSM. Which of the following actions should the team take?

A.Create the KMS key as an asymmetric key in a custom key store and set the key usage to 'SIGN_VERIFY'.
B.Enable the 'Prevent key material export' option in the KMS key policy.
C.Create the KMS key as a symmetric key in the default key store.
D.Create the KMS key in a custom key store and set the key usage to 'ENCRYPT_DECRYPT'.
AnswerD

Creating a symmetric KMS key in a CloudHSM-backed custom key store with key usage set to ENCRYPT_DECRYPT ensures that the key material is generated and used only inside the customer's dedicated HSM cluster. The HSM performs all encryption and decryption operations for that key, and the unencrypted key material never leaves the HSM or becomes visible to AWS KMS service processes. This satisfies both the HSM residency requirement and the need for a general-purpose data encryption key.

Why this answer

To ensure key material never leaves the HSM and cryptographic operations are performed within the HSM, the team should create the KMS key in a custom key store (backed by CloudHSM) and set the key usage to ENCRYPT_DECRYPT. This ensures that the key material is stored and used only within the HSM. Option A is incorrect because asymmetric keys with SIGN_VERIFY usage are not the standard for encryption/decryption, and the key material could potentially be exported if the HSM allows.

Option B is incorrect because the 'Prevent key material export' option is not available in KMS; custom key stores inherently prevent export. Option C is incorrect because the default key store uses software-based keys, not HSM hardware. Therefore, Option D is the correct answer.

41
MCQeasy

A company needs to encrypt data in transit between an EC2 instance and an RDS database. Which option should be used?

A.Enable encryption at rest for the RDS instance
B.Configure the database to use SSL/TLS connections
C.Use an AWS KMS key to encrypt the connection
D.Enable EBS encryption on the EC2 instance
AnswerB

To encrypt data in transit, you must configure the database client and server to negotiate a TLS session. On RDS, this means importing the Amazon RDS CA certificate into the client's trust store and setting the database parameter group's `rds.force_ssl` (PostgreSQL) or `require_secure_transport` (MySQL/MariaDB) parameter to 1. Once enabled, TLS encrypts the entire database protocol stream, including authentication, query text, and result sets, and the client can verify that it is connecting to the genuine RDS endpoint, not an impostor.

Why this answer

Encrypting data in transit between an EC2 instance and an RDS database requires the use of SSL/TLS protocols to secure the communication channel. AWS RDS supports SSL/TLS connections by enabling the `require_secure_transport` parameter or using a certificate bundle on the client side, ensuring that all data transmitted over the network is encrypted and protected from eavesdropping or man-in-the-middle attacks.

Exam trap

The trap here is that candidates often confuse encryption at rest (EBS or RDS encryption) with encryption in transit, or mistakenly think that KMS keys can be directly applied to network connections, when in fact SSL/TLS is the correct mechanism for securing data in motion.

How to eliminate wrong answers

Option A is wrong because encryption at rest protects data stored on disk, not data transmitted over the network between EC2 and RDS. Option C is wrong because AWS KMS is used to manage encryption keys for data at rest or envelope encryption, not to directly encrypt network connections; SSL/TLS uses certificates and cipher suites, not KMS keys. Option D is wrong because EBS encryption protects data at rest on the EC2 instance's volumes, not data in transit between the instance and the RDS database.

42
MCQhard

A company uses AWS KMS to encrypt data in Amazon S3. The security team needs to audit all KMS key usage, including who used the key, when, and what operation was performed. Which AWS service should be used to meet this requirement?

A.AWS CloudTrail
B.Amazon GuardDuty
C.AWS Config
D.AWS CloudHSM
AnswerA

AWS CloudTrail is correct because it records KMS API calls, including management-plane operations like CreateKey, ScheduleKeyDeletion, and PutKeyPolicy, and data-plane operations such as Encrypt, Decrypt, and GenerateDataKey when data events are enabled. When an S3 object encrypted with SSE-KMS is accessed, CloudTrail generates an event for the corresponding KMS Decrypt call, providing a complete audit trail of who used which key, when, and from what context. These logs can be delivered to an S3 bucket and optionally sent to CloudWatch Logs for alerting and forensic analysis, making CloudTrail the definitive service for KMS-related audit and compliance.

Why this answer

AWS CloudTrail is the correct service because it records all AWS KMS API calls as events, including who made the request, the source IP address, the time of the request, and the specific operation performed (e.g., Encrypt, Decrypt, GenerateDataKey). These audit logs are stored in an S3 bucket and can be analyzed to meet the security team's requirement for full key usage auditing.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance monitoring with CloudTrail's API auditing, or assume GuardDuty's threat detection includes detailed usage logs, when in fact only CloudTrail provides the granular, user-specific API call records required for auditing KMS key usage.

How to eliminate wrong answers

Option B (Amazon GuardDuty) is wrong because it is a threat detection service that monitors for malicious activity using anomaly detection and threat intelligence, not a service that records detailed API-level audit logs of KMS key usage. Option C (AWS Config) is wrong because it evaluates resource configurations and compliance rules (e.g., whether KMS keys have automatic rotation enabled), but it does not capture who performed KMS operations or when they occurred. Option D (AWS CloudHSM) is wrong because it provides dedicated hardware security modules for key generation and storage, but it does not generate audit logs of API calls; CloudHSM logs are limited to HSM-level events and require separate integration with CloudTrail for API auditing.

43
MCQmedium

A company is using Amazon S3 to store backup files that must be retained for 7 years. The files are accessed infrequently but must be available within minutes when needed. The company wants to minimize storage costs while ensuring data is encrypted at rest. Which storage class and encryption combination is most cost-effective?

A.S3 Glacier Instant Retrieval with SSE-S3
B.S3 Glacier Deep Archive with SSE-S3
C.S3 Glacier Flexible Retrieval with SSE-KMS
D.S3 Standard-IA with SSE-KMS
AnswerA

S3 Glacier Instant Retrieval provides millisecond access to backup files while offering a lower storage price than S3 Standard-IA, making it both fast and cost-effective for backups that must be available immediately. Using SSE-S3 for encryption adds no per-object or per-API charges, so you satisfy the server-side encryption requirement without increasing the cost of the solution. This combination directly meets the stated need for instant retrieval and economical long-term storage.

Why this answer

S3 Glacier Instant Retrieval provides millisecond retrieval (meeting the 'within minutes' requirement) at lower cost than S3 Standard-IA, and SSE-S3 provides encryption at rest at no additional cost. This combination minimizes storage costs while meeting access and encryption requirements.

Exam trap

The trap is choosing Glacier Deep Archive for cost savings while ignoring the retrieval time requirement, or assuming SSE-KMS is required for encryption when SSE-S3 is sufficient and free.

How to eliminate wrong answers

Option B is wrong because Glacier Deep Archive has retrieval times of 12 hours, not minutes, so it fails the availability requirement. Option C is wrong because Glacier Flexible Retrieval has retrieval times of 1-5 minutes (or minutes to hours), which may meet 'within minutes' but is more expensive than Instant Retrieval for frequent access, and SSE-KMS adds cost. Option D is wrong because S3 Standard-IA is more expensive than Glacier Instant Retrieval for long-term storage and SSE-KMS adds KMS costs.

44
MCQeasy

A company uses S3 to store sensitive customer data. Which AWS service can automatically discover and classify this data to help meet compliance requirements?

A.Amazon GuardDuty
B.AWS Config
C.Amazon CloudWatch
D.Amazon Macie
AnswerD

Amazon Macie is purpose-built to discover, monitor, and classify sensitive data stored in Amazon S3 using machine learning and built-in managed data identifiers such as personally identifiable information (PII), financial data, and credentials. It automatically inventories buckets, evaluates object-level risk, and generates actionable findings/alerts when sensitive data is detected. This makes Macie the correct answer for automatically discovering and classifying sensitive customer data.

Why this answer

Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data stored in Amazon S3. It specifically identifies PII, PHI, credentials, and other sensitive content, generating findings that support compliance requirements such as GDPR, HIPAA, and PCI-DSS. This is the exact purpose for which Macie was designed.

Exam trap

SCS-C02 often tests the distinction between services that detect threats (GuardDuty) versus services that classify data content (Macie) — candidates frequently confuse GuardDuty's S3 protection with Macie's data classification role.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior using VPC Flow Logs, CloudTrail, and DNS logs — it does not classify or discover sensitive data content in S3. Option B is wrong because AWS Config is a configuration compliance service that records resource configuration changes and evaluates them against rules; it does not inspect data content for sensitive information. Option C is wrong because Amazon CloudWatch is a monitoring and observability service for metrics, logs, and alarms — it has no data classification or sensitive-data discovery capability.

45
MCQhard

Refer to the exhibit. A security engineer is reviewing the bucket encryption configuration. The bucket is used to store sensitive data. The company policy requires that all objects be encrypted using AWS KMS with a customer managed key. What should the engineer do to meet the policy?

A.Enable the bucket key and set SSEAlgorithm to AES256
B.Use client-side encryption with a KMS key
C.Update the bucket encryption configuration to use SSEAlgorithm: aws:kms and specify a KMS key ID
D.Add a bucket policy that requires kms:Encrypt permission for all PutObject requests
AnswerC

Changes default encryption to SSE-KMS.

Why this answer

The company policy requires AWS KMS with a customer managed key, which corresponds to SSE-KMS with SSEAlgorithm set to aws:kms and an explicit KMS key ID (or ARN) in the bucket's default encryption configuration. Updating the bucket encryption configuration via PutBucketEncryption with the KMS key ARN satisfies the requirement for all newly uploaded objects.

Exam trap

The trap is equating 'encrypted at rest' with 'KMS customer managed key' — SSE-S3 also encrypts at rest but gives the customer no control over key rotation, which is the actual policy requirement.

How to eliminate wrong answers

Option A is wrong because AES256 corresponds to SSE-S3 (Amazon S3-managed keys), not KMS customer managed keys; bucket keys are a cost optimization for SSE-KMS, not a substitute for it. Option B is wrong because client-side encryption shifts key management to the application and does not use the bucket's default encryption configuration — it also does not meet a policy that specifically mandates AWS KMS with a CMK. Option D is wrong because a bucket policy requiring kms:Encrypt controls authorization, not the actual encryption mechanism; without the bucket encryption configuration set to aws:kms, objects could still be stored with SSE-S3.

46
MCQhard

A security engineer is troubleshooting an issue where an Amazon RDS for MySQL DB instance is not encrypting data at rest. The DB instance was created without encryption. The engineer needs to enable encryption without significant downtime. What is the MOST effective approach?

A.Take a snapshot of the DB instance and enable encryption on the snapshot
B.Take a snapshot, copy it with encryption enabled, and restore a new DB instance from the encrypted snapshot
C.Modify the DB instance and enable encryption in the console
D.Create a read replica with encryption and promote it
AnswerB

Take a manual snapshot of the unencrypted DB instance, then use the AWS CLI or console to copy that snapshot into a new snapshot encrypted with a KMS key (for example, with the copy-db-snapshot command and a --kms-key-id parameter). Once the encrypted snapshot is available, restore a new DB instance from it. The restored instance inherits the encrypted storage from the snapshot, and after updating the application connection string to the new endpoint, the original unencrypted instance can be decommissioned.

Why this answer

To enable encryption on an unencrypted RDS DB instance with minimal downtime, you must take a snapshot, copy it with encryption enabled, and then restore a new DB instance from the encrypted snapshot. This creates a new encrypted instance, and you can then switch applications to it. The process requires some downtime during the switch, but it's the most effective method because RDS does not support enabling encryption in-place on an existing unencrypted instance.

Exam trap

SCS-C02 often tests the misconception that you can enable encryption on an existing RDS instance via modification; candidates may select option C, not realizing encryption must be set at creation or via snapshot restore.

How to eliminate wrong answers

Option A is wrong because you cannot enable encryption directly on an existing snapshot; you must copy it with encryption. Option C is wrong because you cannot modify an existing DB instance to enable encryption; encryption can only be set at creation. Option D is wrong because creating an encrypted read replica is not possible if the source is unencrypted; read replicas inherit the encryption status of the source.

47
MCQhard

A security engineer applies the above S3 bucket policy. An application tries to upload an object with the header "x-amz-server-side-encryption: AES256". What will happen?

A.The upload succeeds because the policy allows SSE-S3.
B.The upload fails because the encryption header does not match 'aws:kms'.
C.The upload succeeds because the object is encrypted.
D.The upload fails because the header is missing.
AnswerB

The bucket policy condition requires the aws:kms encryption algorithm, but the request specifies AES256. Since the header value fails the condition, S3 rejects the PutObject call with an access denied error rather than storing the object.

Why this answer

The bucket policy explicitly requires the condition that the encryption header equals 'aws:kms', which enforces SSE-KMS. When the application sends 'x-amz-server-side-encryption: AES256' (which requests SSE-S3), the request does not satisfy the policy condition, so S3 denies the upload with an AccessDenied error. The policy's condition is a hard gate, not a preference.

Exam trap

SCS-C02 often tests the difference between 'the request is encrypted' and 'the request satisfies the policy condition' — candidates see AES256 and assume encryption is enough, missing that the policy demands a specific encryption type.

How to eliminate wrong answers

Option A is wrong because although SSE-S3 is a valid encryption method, the bucket policy does not allow it — the policy specifically conditions on 'aws:kms', so a valid encryption method that doesn't match the policy still fails. Option C is wrong because the object being encrypted is irrelevant; the policy evaluates the request headers against the condition, and the header value 'AES256' fails the 'aws:kms' check. Option D is wrong because the header is present — it's just the wrong value; the failure is a mismatch, not a missing header.

48
MCQeasy

A company needs to ensure that data in transit between an EC2 instance and an RDS database is encrypted. Which solution meets this requirement?

A.Use a VPN connection between the VPC and the database
B.Enable encryption at rest on the RDS instance
C.Enable SSL/TLS on the database connection
D.Use client-side encryption on the application
AnswerC

Enabling SSL/TLS encrypts the wire protocol between the EC2 client and the RDS endpoint, directly satisfying the in-transit encryption requirement. RDS supports TLS via certificate-based handshake, so the connection itself is protected regardless of storage-level encryption. This is the only option addressing data moving across the network.

Why this answer

SSL/TLS is the appropriate solution to encrypt data in transit between the EC2 instance and the RDS database. It ensures that data is encrypted during transmission, preventing eavesdropping or tampering. Option A is incorrect because a VPN connection encrypts traffic between networks but is unnecessary for direct connectivity within the same VPC; SSL/TLS is more straightforward.

Option B is incorrect because encryption at rest protects data stored on disk, not data in motion. Option D is incorrect because client-side encryption would require modifying the application to encrypt data before sending, which does not guarantee encryption of the entire communication channel.

49
MCQeasy

A company wants to protect data in transit between an on-premises data center and Amazon S3. Which AWS service should be used to establish a dedicated, encrypted connection?

A.AWS Direct Connect without VPN
B.AWS Transit Gateway
C.AWS Direct Connect with an IPsec VPN
D.AWS Site-to-Site VPN over the internet
AnswerC

AWS Direct Connect with an IPsec VPN layers an encrypted VPN tunnel over a dedicated, private Direct Connect connection, giving you both isolation from the public internet and traffic confidentiality. The IPsec protocol authenticates and encrypts the packets, ensuring that data is protected in transit while still benefiting from the predictable latency and throughput of the physical link. This is the recommended pattern when you need both dedicated bandwidth and encryption.

Why this answer

AWS Direct Connect alone provides a dedicated private network path but does not encrypt traffic in transit. To achieve both a dedicated connection and encryption, you must pair Direct Connect with an IPsec VPN running over the dedicated link. This combination gives the private, consistent bandwidth of Direct Connect plus the encryption guarantees of IPsec, satisfying the requirement for encrypted data in transit.

Exam trap

SCS-C02 often tests the misconception that Direct Connect is encrypted by default — candidates must remember that encryption requires an explicit IPsec VPN or MACsec layer on top of the dedicated connection.

How to eliminate wrong answers

Option A is wrong because Direct Connect without VPN does not encrypt traffic — data travels in plaintext over the dedicated circuit. Option B is wrong because Transit Gateway is a network hub for connecting VPCs and on-premises networks, not an encryption or dedicated-connection service. Option D is wrong because Site-to-Site VPN over the public internet is encrypted but does not provide a dedicated connection, and its performance is subject to internet variability.

50
Multi-Selecthard

A company needs to protect data in Amazon S3 by ensuring that only authorized users can access objects, and all access is logged. Which TWO services should be used together? (Choose TWO.)

Select 2 answers
A.AWS Identity and Access Management (IAM)
B.AWS CloudTrail
C.AWS KMS
D.AWS WAF
E.Amazon CloudWatch
AnswersA, B

AWS Identity and Access Management enforces authentication and authorisation through policies, satisfying the stem's requirement that only authorised users access S3 objects. It provides the permission boundary, while a logging service supplies the audit trail of that access.

Why this answer

AWS Identity and Access Management (IAM) is correct because it enables you to define granular permissions for S3 objects, ensuring that only authorized users or roles can access them via IAM policies or S3 bucket policies. AWS CloudTrail is correct because it logs all API calls made to S3, including object-level operations like GetObject and PutObject, providing an audit trail for access. Together, they satisfy the requirement of controlling access and logging all access.

Exam trap

The trap here is that candidates often confuse AWS KMS with access control because encryption is related to data protection, but KMS does not authorize user access or log access events, which are the core requirements in this question.

51
MCQeasy

A company wants to encrypt data stored in Amazon S3 using server-side encryption with customer-provided keys (SSE-C). Which statement is correct regarding SSE-C?

A.The customer provides the encryption key in each request to S3.
B.AWS manages the encryption keys.
C.The same encryption key is used for all objects in the bucket.
D.The encryption key is stored in AWS KMS.
AnswerA

Under SSE-C, the customer must provide the encryption key in the headers of every S3 request, such as x-amz-server-side-encryption-customer-key. S3 uses that key to encrypt the object at write time and to decrypt it at read time, then discards the key after the request completes. Because the key is never stored by AWS, it must be supplied again for each upload, download, or header retrieval.

Why this answer

SSE-C requires the customer to provide the encryption key and its MD5 digest in every PUT or GET request to Amazon S3. S3 uses the key to encrypt the object at rest and then discards the key; it is never stored by AWS. This ensures the customer retains full control over the encryption key material.

Exam trap

The trap here is that candidates confuse SSE-C with SSE-S3 or SSE-KMS, assuming AWS manages the keys or that keys are stored in KMS, when in fact SSE-C requires the customer to supply the key with every request and AWS never retains it.

How to eliminate wrong answers

Option B is wrong because SSE-C explicitly does not involve AWS managing the keys; the customer provides and manages the key. Option C is wrong because SSE-C requires a unique encryption key per request; the same key is not reused for all objects in the bucket unless the customer deliberately sends the same key each time. Option D is wrong because the encryption key is not stored in AWS KMS; SSE-C keys are provided by the customer in each request and are not persisted by AWS.

52
MCQeasy

A company needs to encrypt data at rest in its Amazon EBS volumes. The company wants to use an encryption key that is automatically rotated every year without any manual intervention. Which key type should be used?

A.Imported key material in a customer managed key
B.AWS managed key for EBS
C.Customer managed key with manual rotation
D.Default EBS encryption using an AWS managed key
AnswerB

The AWS managed key for EBS (aws/ebs) is a KMS key that AWS creates and manages in the customer's account, and AWS KMS automatically rotates it once per year. Because EBS volumes can use this key by default and no customer action is required for rotation, it satisfies the requirement for automatic rotation. This is the key type that the question is asking to identify.

Why this answer

AWS managed keys are automatically rotated annually. Option B (AWS managed key for EBS) is correct because this key type handles rotation automatically without any manual intervention. Option A (Imported key material in a customer managed key) is incorrect because imported key material does not support automatic rotation.

Option C (Customer managed key with manual rotation) is incorrect because even though automatic rotation can be enabled on a customer managed key, the key type itself requires enabling rotation; the question implies a managed solution without manual setup. Option D (Default EBS encryption using an AWS managed key) is incorrect because it refers to an encryption setting, not a key type, and the question asks for the key type.

53
MCQeasy

A company needs to ensure that data in transit between an on-premises data center and Amazon S3 is encrypted. Which AWS service should be used to establish a dedicated encrypted connection?

A.AWS Transit Gateway
B.AWS Site-to-Site VPN
C.AWS Direct Connect with VPN
D.AWS Client VPN
AnswerC

AWS Direct Connect with VPN is the correct combination because Direct Connect gives you a dedicated, private network connection that bypasses the public internet, offering consistent latency and bandwidth. Since Direct Connect alone does not encrypt your traffic, the VPN overlay (typically IPsec) is added to encrypt data in transit over that private connection. This pairing satisfies both explicit requirements: a dedicated transport path and encryption for all data between the on-premises environment and AWS.

Why this answer

AWS Direct Connect provides a dedicated, private network connection from an on-premises data center to AWS, but it does not inherently encrypt data in transit. By combining Direct Connect with a VPN (IPsec tunnel), you get both a dedicated connection and encryption of all traffic between the on-premises network and Amazon S3. This ensures data in transit is protected while avoiding the public internet.

Exam trap

The trap here is that candidates often assume Direct Connect alone provides encryption, but it does not—it only provides a private, dedicated physical link; encryption must be added via a VPN overlay, which is why the combination is the correct answer.

How to eliminate wrong answers

Option A is wrong because AWS Transit Gateway is a network transit hub that connects VPCs and on-premises networks, but it does not itself provide encryption or a dedicated connection; it can route traffic over VPN or Direct Connect but is not the service that establishes the encrypted link. Option B is wrong because AWS Site-to-Site VPN uses the public internet to create an encrypted tunnel, which does not provide a dedicated connection; it relies on internet routing and can suffer from variable latency and bandwidth. Option D is wrong because AWS Client VPN is a managed remote access VPN service for individual clients (e.g., laptops) to connect to AWS, not for establishing a dedicated encrypted connection between an entire on-premises data center and S3.

54
MCQeasy

A company is migrating sensitive data to Amazon S3. The data must be encrypted at rest using keys managed by the company. The company also requires an audit trail of key usage. Which solution meets these requirements?

A.Use SSE-S3 with default encryption.
B.Use SSE-C and store the keys in AWS Secrets Manager.
C.Use SSE-KMS with a customer-managed key and enable CloudTrail for KMS.
D.Use AWS CloudHSM to generate and store keys, and use Amazon S3 with SSE-KMS.
AnswerC

SSE-KMS with a customer-managed key gives you independent control over the CMK, including the ability to set key policies, grant and revoke permissions, and force rotation. With CloudTrail for KMS enabled, every Decrypt, GenerateDataKey, and ReEncrypt request against that key is recorded with the user, role, and principal ARN, directly tying each S3 object access to an auditable event. Customer-managed keys also let you align the key with your own governance model, and because the key is in KMS, you can use key policies to enforce conditions (such as VPC endpoints or MFA) and can respond to a breach by disabling the key to instantly block all future decrypt operations.

Why this answer

SSE-KMS with a customer-managed key and CloudTrail for KMS. This solution meets both requirements: the company manages its own keys (customer-managed CMK) and CloudTrail logs every KMS API call, providing an audit trail of key usage. Option A (SSE-S3) uses Amazon-managed keys, so no customer control or audit trail.

Option B (SSE-C) requires the customer to manage keys themselves but does not integrate with CloudTrail for key usage auditing; also, storing keys in Secrets Manager does not provide an audit trail of KMS key usage. Option D (CloudHSM) can be used, but it requires more complex setup for auditing; SSE-KMS with CloudTrail is the simpler and more direct solution.

55
Multi-Selectmedium

Which TWO of the following are valid ways to enforce encryption at rest for data in Amazon S3? (Choose TWO.)

Select 2 answers
A.Use SSL/TLS
B.Use IAM policies
C.Use AWS CloudTrail
D.Use SSE-KMS
E.Use SSE-C
AnswersD, E

SSE-KMS (Server-Side Encryption with AWS KMS) instructs S3 to encrypt each object at rest using a customer managed KMS key, AWS managed KMS key, or AWS owned key. S3 calls KMS to generate a plaintext data key and an encrypted copy of that key, using envelope encryption to protect the object while maintaining the ability to rotate the KMS key independently. This gives you separation of duties, centralized key management, and auditability, making it a valid way to enforce at-rest encryption.

Why this answer

SSE-KMS (option D) is correct because it enforces server-side encryption at rest by having Amazon S3 encrypt objects with keys managed in AWS KMS, providing envelope encryption and auditability via CloudTrail. SSE-C (option E) is also correct because it enforces server-side encryption at rest using a customer-provided encryption key that S3 applies to the object, so data is stored encrypted on disk. Option A (SSL/TLS) is incorrect because it only protects data in transit between the client and S3, not data at rest.

Option B (IAM policies) is incorrect because IAM controls authorization and permissions, not the encryption of stored objects. Option C (CloudTrail) is incorrect because it records API activity for auditing, not encryption of data at rest.

Exam trap

SCS-C02 often tests the difference between encryption in transit and at rest; candidates may select SSL/TLS or IAM policies, but those do not enforce encryption at rest.

56
MCQeasy

Refer to the exhibit. A security engineer runs the above AWS CLI command to encrypt a secret file. The command succeeds and returns a base64-encoded ciphertext. Which of the following statements is correct?

A.The command returns a plaintext data key and an encrypted copy.
B.The command will fail because fileb:// is not a valid prefix.
C.The command returns a base64-encoded ciphertext that can be decrypted with the same KMS key.
D.The command will fail because encryption context is required.
AnswerC

The kms encrypt API returns a CiphertextBlob, and the AWS CLI base64-encodes this binary field in its JSON output. The ciphertext is encrypted under the customer master key specified in the command, so the same KMS key can decrypt it by calling kms decrypt after base64-decoding the blob. This matches the actual behavior of the command and is therefore the correct answer.

Why this answer

The command encrypts the plaintext file using the specified KMS key and returns the ciphertext as base64-encoded output. Option A is wrong because the command does not specify an encryption context; it's optional. Option B is wrong because the command uses fileb:// which reads binary data; it will succeed if the file exists.

Option D is wrong because the output is the ciphertext, not a data key.

57
MCQmedium

A company uses AWS Secrets Manager to rotate database credentials automatically. The security team wants to ensure that while the secret is being rotated, applications can always retrieve a valid credential. Which rotation strategy should be used?

A.Use AWS IAM database authentication instead.
B.Use a single user rotation with immediate update.
C.Disable automatic rotation and manually update credentials.
D.Use the alternating users rotation strategy.
AnswerD

The alternating users rotation strategy creates a second set of database credentials while the original remains valid, then promotes the new credentials to AWSCURRENT and demotes the old ones to AWSPREVIOUS. Applications can continue using either credential during the transition, so there is no window where no valid password exists. This makes it the right choice when a database cannot tolerate even brief downtime during Secrets Manager rotation.

Why this answer

The alternating users rotation strategy (Option D) is correct because it creates two sets of credentials—one active and one pending—so that during rotation, at least one set remains valid for applications. Option A (IAM database authentication) is not a rotation strategy for Secrets Manager. Option B (single user rotation with immediate update) would cause a brief period where the credential is invalid, leading to potential downtime.

Option C (disabling automatic rotation) defeats the purpose of automated rotation.

Exam trap

Candidates may mistakenly believe that single user rotation (Option B) is acceptable, but it causes a temporary gap in valid credentials. The alternating users strategy avoids this gap.

58
MCQhard

A company stores sensitive data in an Amazon S3 bucket. The security team wants to ensure that all objects are encrypted with SSE-KMS using a specific customer managed key, and that any attempt to upload an object without this encryption is denied. The bucket policy must enforce this. Which bucket policy statement should the security engineer use?

A.Two deny statements for s3:PutObject: one where StringNotEquals on s3:x-amz-server-side-encryption is 'aws:kms', and another where StringNotEquals on s3:x-amz-server-side-encryption-aws-kms-key-id is the ARN of the specific KMS key.
B.A deny statement for s3:PutObject where the condition StringNotEquals on s3:x-amz-server-side-encryption is 'aws:kms' AND StringNotEquals on s3:x-amz-server-side-encryption-aws-kms-key-id is the ARN of the specific KMS key.
C.A deny statement for s3:PutObject where the condition StringNotEquals on s3:x-amz-server-side-encryption-aws-kms-key-id is the ARN of the specific KMS key.
D.A deny statement for s3:PutObject where the condition StringNotEquals on s3:x-amz-server-side-encryption is 'aws:kms'.
AnswerA

Two separate deny statements ensure that an upload is denied if it lacks the correct encryption algorithm or if it uses a different KMS key. The first statement denies any upload not using aws:kms. The second denies any upload not using the specified key ARN. Together they enforce both requirements. This is the recommended approach in AWS documentation.

Why this answer

To enforce a specific KMS key for SSE-KMS, the bucket policy must deny uploads that either do not use SSE-KMS or do not use the specified key. Using two separate deny statements with StringNotEquals conditions on s3:x-amz-server-side-encryption and s3:x-amz-server-side-encryption-aws-kms-key-id achieves this. A single statement with AND logic would not correctly deny when only one condition is violated.

Exam trap

The trap here is combining conditions with AND in a single deny statement, which fails to deny when only one condition is not met, leaving a gap in enforcement.

59
MCQhard

A financial services company uses AWS KMS to encrypt sensitive data. The security team has a requirement to rotate the CMK every 90 days and to maintain a record of all previous key versions for decryption of historical data. The team creates a new CMK every 90 days and manually updates applications to use the new key. This process is error-prone and causes downtime. What is the MOST operationally efficient solution that meets the requirements?

A.Enable automatic key rotation on the existing CMK.
B.Create a new CMK every 90 days and update the alias to point to the new key. Applications reference the alias.
C.Use a CMK with imported key material and rotate the material every 90 days.
D.Continue creating new CMKs but use a script to update the application configuration files.
AnswerB

Creating a new CMK every 90 days and then updating the alias to reference the new key provides a stable abstraction because applications point to the alias, not the key ID. The alias update is immediate and atomic, requiring no application changes, restarts, or downtime; the old CMK remains enabled to decrypt data encrypted under previous keys. This pattern is the recommended AWS KMS approach for custom rotation periods and satisfies crypto-period separation.

Why this answer

It uses aliases to decouple the key identifier from the application configuration. By creating a new CMK every 90 days and updating the alias to point to the new key, applications that reference the alias automatically use the new key without code changes, eliminating downtime. AWS KMS aliases are mutable pointers that can be reassigned to different CMKs, and the old key versions remain available for decryption of historical data.

Exam trap

The trap here is that candidates often confuse automatic key rotation (which only rotates backing keys within the same CMK) with creating a new CMK and using aliases, failing to recognize that automatic rotation does not meet a 90-day schedule and does not create a separate CMK for audit or compliance purposes.

How to eliminate wrong answers

Option A is wrong because automatic key rotation on an existing CMK creates new backing key versions every year (not 90 days) and does not create a new CMK; it only rotates the cryptographic material within the same CMK, which does not meet the 90-day rotation requirement. Option C is wrong because using a CMK with imported key material and rotating the material every 90 days still does not create a new CMK; it only replaces the key material within the same CMK, and the old key material is deleted, preventing decryption of historical data. Option D is wrong because it continues the error-prone manual process of updating application configuration files, which causes downtime and operational overhead, and does not leverage AWS KMS aliases for a seamless transition.

60
MCQeasy

Refer to the exhibit. An AWS KMS key policy includes the statement shown. The AdminRole tries to decrypt a ciphertext that was encrypted using the same KMS key with encryption context 'department=engineering'. What will happen?

A.The decrypt operation succeeds because the role has kms:Decrypt permission.
B.The decrypt operation succeeds because the encryption context is ignored during decryption.
C.The decrypt operation fails because the policy does not allow kms:Decrypt without matching context.
D.The decrypt operation fails because the encryption context does not match the condition.
AnswerD

The key policy scopes kms:Decrypt to calls whose encryption context contains department=finance. The decrypt request supplies a different encryption context, so the kms:EncryptionContext:department condition key does not match. As a result, the condition in the key policy is false and KMS denies the Decrypt operation. This is expected behavior: encryption context conditions are a way to limit key usage to specific data or workloads.

Why this answer

The KMS key policy includes a condition that requires the encryption context to be 'department=finance' for decryption. When the AdminRole attempts to decrypt, the encryption context must match both the encryption context used during encryption and any conditions in the key policy. Since the ciphertext was encrypted with 'department=engineering', the decryption fails because the encryption context does not satisfy the policy condition, even though the role has kms:Decrypt permission.

Exam trap

The trap here is that candidates assume kms:Decrypt permission alone is sufficient for decryption, overlooking that encryption context conditions in the key policy can override the permission and cause a failure even when the IAM role has the correct action allowed.

How to eliminate wrong answers

Option A is wrong because having kms:Decrypt permission alone is insufficient; the policy also includes a condition that restricts decryption to requests with a matching encryption context. Option B is wrong because the encryption context is not ignored during decryption; AWS KMS requires the same encryption context to be provided for decryption as was used during encryption, and the policy enforces this with a condition. Option C is wrong because the policy does allow kms:Decrypt, but only when the encryption context matches; the failure is due to the context mismatch, not a lack of permission.

61
Multi-Selecthard

A company is designing a data protection strategy for Amazon EFS file systems. The security team requires encryption at rest and in transit. Additionally, the team needs to control which KMS keys can be used to encrypt the file system. Which THREE steps should the team take?

Select 3 answers
A.Configure a KMS key policy that allows the EFS service to use the key.
B.Enable encryption at rest using a customer-managed KMS key when creating the EFS file system.
C.Enable default encryption on the EFS file system using SSE-S3.
D.Use an IAM policy to restrict which users can create encrypted file systems.
E.Enable encryption of data in transit using the mount helper's tls option on the client.
AnswersA, B, E

The KMS key policy acts as the resource-based authorization for the key and must explicitly grant the Amazon EFS service principal (elasticfilesystem.amazonaws.com) the kms:GenerateDataKeyWithoutPlaintext, kms:Decrypt, and kms:DescribeKey permissions. Without these grants in the key policy, EFS cannot create or use data keys to encrypt or decrypt the file system, even if the IAM principal has full EFS permissions. This is a mandatory, non-optional part of enabling EFS encryption at rest — the key policy is the authoritative control over which AWS services may use the CMK. Therefore, configuring the key policy correctly is a required action, not merely a best practice.

Why this answer

Option A is correct because the KMS key policy must explicitly grant the EFS service principal (elasticfilesystem.amazonaws.com) permission to use the customer-managed key for cryptographic operations; without this, EFS cannot use the key to encrypt or decrypt file data. Option B is correct because encryption at rest on EFS is enabled at file-system creation time by specifying a customer-managed KMS key, which is exactly how the team controls which key protects the file system. Option E is correct because EFS encryption in transit is achieved by mounting with the TLS option via the EFS mount helper (for example, using -o tls with amazon-efs-utils), which enforces TLS 1.2 for NFS traffic.

Option C is wrong because EFS does not support SSE-S3; that is an Amazon S3 server-side encryption option, and EFS uses KMS keys instead. Option D is wrong because an IAM policy restricting who can create encrypted file systems does not itself enable encryption at rest or in transit, nor does it control which KMS keys are used for a given file system.

Exam trap

The trap is confusing EFS encryption with S3 SSE-S3 or thinking IAM policies can control KMS key usage; EFS uses KMS and requires key policy configuration.

62
MCQhard

A company uses AWS CloudHSM to generate and store encryption keys for a custom application. The application runs on Amazon EC2 instances and uses the PKCS#11 interface to interact with the HSM. The security team recently discovered that a former employee may have obtained a copy of the cryptographic materials from the HSM. What should the security team do to minimize the impact?

A.Use AWS KMS to create a new key and re-encrypt all data. Then revoke the old key.
B.Delete the CloudHSM backup from the backup service. Then rotate all keys that were stored in the HSM.
C.Change the HSM administrator password and the crypto user passwords.
D.Delete the HSM cluster and create a new one. Restore the backup from a known good time.
AnswerB

Deleting the CloudHSM backup from the backup service ensures that the copied encrypted key material that was exfiltrated cannot be restored to a new or existing HSM, eliminating the attacker's ability to recover the keys. After that, rotating every key that was stored in the HSM—generating new keys and re-encrypting data with them—renders any previously copied key material useless because the data is now protected by fresh keys. This two-step approach directly addresses both ways the compromise can be exploited: backup restoration and continued use of the old key material.

Why this answer

Deleting the CloudHSM backup prevents the former employee from restoring the HSM's contents from a backup. Rotating all keys ensures that any keys the employee may have copied are no longer valid for encrypting/decrypting data, minimizing the impact of the exposure. Option A is incorrect because AWS KMS cannot manage keys stored in CloudHSM.

Option C is incorrect because changing passwords does not invalidate cryptographic material that has already been copied. Option D is incorrect because deleting the HSM cluster alone does not delete the backup, and restoring from an old backup may reintroduce the compromised keys.

63
MCQhard

A company uses Amazon SQS to decouple its microservices. The messages contain personally identifiable information (PII). The security team requires that all messages be encrypted at rest. Currently, SQS is configured with SSE enabled using a customer managed KMS key. However, the team discovers that some messages are still being stored in plaintext in the dead-letter queue (DLQ) after the maximum receives are exceeded. The DLQ is also an SQS queue. What is the MOST likely reason?

A.The source queue's SSE is configured with AWS managed KMS key, which does not support cross-account DLQ.
B.The DLQ does not have SSE enabled, so messages are stored in plaintext.
C.The source queue's SSE configuration uses a different KMS key than the DLQ, causing decryption failure.
D.The KMS key policy does not allow the SQS service to decrypt the messages before moving them to the DLQ.
AnswerB

This is correct. SSE is a per-queue setting, so enabling it on the source queue does not automatically protect the DLQ. When a message is redriven, SQS decrypts it from the source queue and writes it to the DLQ using whatever encryption the DLQ has configured. If the DLQ has no SSE, the message is stored as plaintext, directly violating the company's requirement that messages be encrypted at rest.

Why this answer

SSE is configured per queue, not inherited. Enabling SSE with a customer-managed KMS key on the source queue does not automatically encrypt the DLQ; if the DLQ was created without SSE, messages moved there are stored using SQS's default (no encryption at rest) behavior, exposing the PII in plaintext. Each SQS queue, including a DLQ, must have its own encryption configuration.

Exam trap

The trap is assuming encryption settings propagate from a source queue to its DLQ; in SQS, SSE is per-queue, so the DLQ must be encrypted separately.

How to eliminate wrong answers

Option A is wrong because AWS managed keys (aws/sqs) do support DLQs, including cross-account DLQs when the key policy and queue policy permit it; the encryption type is not the cause of plaintext storage. Option C is wrong because using different KMS keys on source and DLQ does not cause decryption failure — SQS decrypts on receive and re-encrypts on send, so the DLQ simply uses its own key; a mismatch does not produce plaintext. Option D is wrong because the KMS key policy governs who can use the key, not whether SQS stores messages encrypted; if the key policy blocked SQS, message delivery would fail with an error rather than silently store plaintext.

64
MCQmedium

A company is using AWS KMS to encrypt S3 objects. The security team wants to ensure that only a specific IAM role can decrypt objects in a particular S3 bucket. Which KMS key policy configuration should be used?

A.Add a condition that allows decrypt only when kms:ViaService is s3.amazonaws.com and the caller role matches the specific role ARN.
B.Use an S3 bucket policy that denies decrypt for all principals except the specific IAM user.
C.Configure the IAM role with a policy that allows kms:Decrypt for the specific KMS key.
D.Attach a resource-based policy to the S3 bucket that grants decrypt permission to the IAM role.
AnswerA

The kms:ViaService condition restricts key usage to requests routed through S3, while the principal or ARN condition limits decryption to the named IAM role. Together they enforce least privilege, ensuring no other principal or direct KMS call can decrypt the bucket's objects.

Why this answer

A KMS key policy with a condition restricting kms:Decrypt to the specific IAM role ARN and kms:ViaService set to s3.amazonaws.com ensures only that role, acting through S3, can decrypt objects. This is the authoritative control because KMS key policies govern all access to the CMK, and the ViaService condition prevents the role from using the key directly outside S3.

Exam trap

SCS-C02 often tests the misconception that S3 bucket policies can control KMS decrypt — candidates conflate S3 authorization with KMS authorization, but KMS key policies are the authoritative gate.

How to eliminate wrong answers

Option B is wrong because an S3 bucket policy cannot grant or deny KMS decrypt permissions — KMS authorization is controlled by the key policy and IAM, not S3 policies. Option C is wrong because an IAM policy alone is insufficient; the KMS key policy must also allow the role, otherwise the request is denied (unless the key policy delegates to IAM). Option D is wrong because S3 resource-based policies do not govern KMS key usage; decrypt operations are authorized by KMS, not S3.

65
MCQhard

A company has an Amazon S3 bucket with versioning enabled. They want to ensure that all objects in the bucket are encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). They also want to prevent any future uploads that are not encrypted with SSE-KMS. Which combination of actions should they take?

A.Add a bucket policy that denies s3:PutObject if s3:x-amz-server-side-encryption is not aws:kms. Use S3 Inventory to report encryption status of existing objects.
B.Use AWS Config rule s3-bucket-server-side-encryption-enabled to check compliance.
C.Use S3 Object Lock with governance mode.
D.Enable default encryption with SSE-KMS on the bucket. Use S3 Inventory to report encryption status.
AnswerA

This solution combines an explicit bucket policy deny with the s3:x-amz-server-side-encryption condition key to reject any PutObject that does not specify aws:kms as the encryption value, making enforcement happen before the write is committed. Because this is a request-level condition, it cannot be bypassed by client-side SDK settings or explicit SSE headers that differ from KMS. S3 Inventory then provides a periodic CSV or Parquet report of existing objects, including their encryption status, enabling the team to locate and remediate any legacy objects that predate the policy.

Why this answer

A bucket policy denying PutObject without SSE-KMS prevents non-compliant uploads, and S3 Inventory reports encryption status. Option B only checks compliance, does not enforce. Option C does not enforce encryption.

Option D does not enforce.

66
MCQeasy

A company is storing sensitive data in Amazon S3 buckets. They want to ensure that all uploaded objects are encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). Which bucket policy statement will enforce this?

A.{"Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringNotEquals": {"s3:x-amz-server-side-encryption": "aws:kms"}}}
B.{"Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringNotEquals": {"s3:x-amz-server-side-encryption": "AES256"}}}
C.{"Effect": "Allow", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringEquals": {"s3:x-amz-server-side-encryption": "aws:kms"}}}
D.{"Effect": "Deny", "Principal": "*", "Action": "s3:PutObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringEquals": {"s3:x-amz-server-side-encryption": "aws:kms"}}}
AnswerA

This bucket policy is correct because it uses an explicit Deny with a StringNotEquals condition to require that every s3:PutObject request includes the x-amz-server-side-encryption header set to aws:kms. Since explicit Deny statements override any Allow, any upload that lacks the header or uses a different encryption method is blocked, while requests that properly specify SSE-KMS are allowed. The absence of the header also makes StringNotEquals evaluate true, so the Deny also catches requests that omit encryption entirely, ensuring sensitive data is always encrypted with KMS-managed keys.

Why this answer

It uses a Deny effect with a StringNotEquals condition on the s3:x-amz-server-side-encryption header set to 'aws:kms'. This ensures that any PutObject request that does not include the header specifying SSE-KMS is denied, effectively enforcing that all uploaded objects must be encrypted with AWS KMS. The Deny effect overrides any Allow, making this policy robust against accidental or malicious uploads without the required encryption.

Exam trap

The trap here is that candidates often choose an Allow policy (Option C) thinking it enforces encryption, but without a Deny, requests that omit the encryption header are still allowed by default, making the policy ineffective.

How to eliminate wrong answers

Option B is wrong because it enforces SSE-S3 (AES256) instead of SSE-KMS, which does not meet the requirement for server-side encryption with AWS KMS. Option C is wrong because an Allow effect with a StringEquals condition is insufficient; it does not block uploads that lack the encryption header, as the default behavior (no explicit Deny) would allow them. Option D is wrong because it enforces SSE-S3 (AES256) via a Deny, which again is not SSE-KMS and would incorrectly block valid SSE-KMS uploads while allowing non-compliant ones.

67
MCQeasy

A company needs to share an encrypted Amazon S3 object with another AWS account. The object is encrypted with an AWS KMS customer managed key. Which steps are required?

A.Use an object ACL to grant the other account read access.
B.Update both the bucket policy and the KMS key policy to grant cross-account access.
C.Update the bucket policy to allow the other account to access the object.
D.Update the KMS key policy to allow the other account to decrypt.
AnswerB

The correct cross-account configuration requires two resource-based policies that address separate authorization layers: the bucket policy must explicitly allow the external account's principal to call s3:GetObject on the object, and the KMS key policy must explicitly allow that same external principal to call kms:Decrypt. The bucket policy authorizes the S3 data-plane operation, while the KMS key policy authorizes the cryptographic operation that S3 performs on the requester's behalf. Without either policy, the request fails because the external account is not part of the key owner's account and cross-account access is denied by default.

Why this answer

Cross-account access to a KMS-encrypted S3 object requires permissions on both sides: the S3 bucket policy must grant the external account s3:GetObject, and the KMS key policy must grant that account kms:Decrypt. Without the KMS key policy update, the external account's request fails with AccessDenied even if the bucket policy allows it, because S3 delegates decryption authorization to KMS.

Exam trap

SCS-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access to KMS-encrypted objects, ignoring the separate KMS key policy authorization boundary.

How to eliminate wrong answers

Option A is wrong because S3 object ACLs do not grant KMS decrypt permissions — ACLs only control S3-level access, and KMS-encrypted objects still require kms:Decrypt on the key. Option C is wrong because updating only the bucket policy is insufficient; the KMS key policy must also authorize the external account, otherwise decryption fails. Option D is wrong because updating only the KMS key policy without the bucket policy leaves the S3 GetObject call unauthorized.

68
MCQhard

A company uses AWS CloudHSM to store encryption keys for a custom database encryption application. The application runs on Amazon EC2 instances and uses the PKCS#11 library to communicate with the HSM. Recently, the application started failing with 'CKR_SESSION_HANDLE_INVALID' errors. Which of the following is the most likely cause?

A.The client certificate used for mutual TLS authentication has expired
B.The security group for the HSM does not allow inbound traffic from the EC2 instance
C.The application is not closing sessions properly, causing the HSM to reach the maximum number of open sessions
D.The HSM's firmware version is incompatible with the PKCS#11 library
AnswerC

PKCS#11 sessions on a CloudHSM are finite, and each session handle is valid only until C_CloseSession or C_Finalize is called. An application that fails to close sessions leaks them, and once the HSM client's session limit is reached, any handle retained from an evicted or expired session returns CKR_SESSION_HANDLE_INVALID on subsequent operations. This is the correct explanation: the root cause is session lifecycle mismanagement, not network or identity configuration, and the fix is to use try-with-resources or a session pool that guarantees C_CloseSession in all code paths.

Why this answer

CKR_SESSION_HANDLE_INVALID is a PKCS#11 error indicating that the session handle used by the application is no longer valid. This typically occurs when the application opens sessions but fails to close them, eventually exhausting the HSM's maximum session limit. Once the limit is reached, new session requests fail or existing handles become invalid.

Proper session management (closing sessions after use) is required to avoid this error.

Exam trap

The trap is confusing network or authentication errors with PKCS#11 session errors — candidates may pick security group or certificate issues, but the specific error code CKR_SESSION_HANDLE_INVALID points directly to session management on the HSM.

How to eliminate wrong answers

Option A is wrong because an expired client certificate would cause TLS handshake failures or authentication errors, not a PKCS#11 session handle error — the application would not even establish a connection to the HSM. Option B is wrong because a security group blocking inbound traffic would prevent the EC2 instance from connecting to the HSM at all, resulting in connection timeouts or network errors, not CKR_SESSION_HANDLE_INVALID. Option D is wrong because firmware incompatibility would typically cause different errors (e.g., CKR_DEVICE_ERROR or CKR_FUNCTION_NOT_SUPPORTED) and would affect all operations consistently, not manifest as invalid session handles.

69
MCQhard

A company uses Amazon S3 to store sensitive documents. The security policy requires that all objects be encrypted using server-side encryption with customer-provided keys (SSE-C). An application fails when trying to read an object with the error 'The request includes an invalid header.' What is the MOST likely cause?

A.The application did not specify an encryption context in the request.
B.The KMS key used for encryption has been disabled.
C.The application did not include the x-amz-server-side-encryption-customer-key header in the GET request.
D.The S3 bucket does not have versioning enabled.
AnswerC

For an SSE-C encrypted object, S3 does not store or possess the actual encryption key; it only stores a one-way HMAC-derived verification value. Accordingly, every GET request must include the `x-amz-server-side-encryption-customer-key` header, along with `x-amz-server-side-encryption-customer-algorithm` and optionally the MD5 header, so S3 can verify the key and decrypt the object. Omitting the key header in the GET causes S3 to return a 400 Bad Request because it cannot authenticate the customer-supplied key.

Why this answer

With SSE-C, the customer provides the encryption key on every request, and S3 does not store it. For a GET request, the client must include the same key headers used during PUT: x-amz-server-side-encryption-customer-algorithm, x-amz-server-side-encryption-customer-key, and x-amz-server-side-encryption-customer-key-MD5. If the key header is missing, S3 returns an 'invalid header' error because it cannot decrypt the object.

Exam trap

The trap is mixing up SSE-C with SSE-KMS — candidates pick 'encryption context' or 'KMS key disabled' because they forget SSE-C requires the customer key headers on every request, not KMS.

How to eliminate wrong answers

Option A is wrong because encryption context is a KMS concept (used with SSE-KMS for additional authenticated data), not SSE-C; SSE-C does not use encryption context. Option B is wrong because a disabled KMS key would produce a KMS-related error (e.g., KMS.DisabledException), and SSE-C does not use KMS at all. Option D is wrong because bucket versioning is unrelated to encryption headers; versioning affects object retention, not the ability to decrypt on GET.

70
MCQhard

A company has an S3 bucket with versioning enabled. They want to ensure that all deleted objects are retained for 90 days before permanent deletion. Which S3 feature should be used?

A.S3 Lifecycle policy with NoncurrentVersionExpiration
B.S3 Replication
C.S3 Object Lock
D.MFA Delete
AnswerA

S3 Lifecycle policy with NoncurrentVersionExpiration defines how many days a previous version is retained after it becomes noncurrent. When a versioned object is deleted, S3 places a delete marker and the prior version is preserved as a noncurrent version; the lifecycle action permanently removes those noncurrent versions only after the specified number of days. This provides exactly the requested grace period for recovering deleted objects before they are eventually purged.

Why this answer

S3 Lifecycle policies can manage the expiration of noncurrent versions of objects. In this scenario, after an object is deleted, it becomes a noncurrent version. A lifecycle rule with NoncurrentVersionExpiration can be set to permanently delete those noncurrent versions after a specified number of days (e.g., 90).

Option A is correct. S3 Object Lock protects objects from deletion but does not automatically delete them after a period. S3 Replication is for copying objects to another bucket.

MFA Delete adds a multi-factor authentication requirement for deletion but does not set a retention period.

71
MCQmedium

A security engineer needs to protect data in transit between an EC2 instance and an RDS database. The RDS database uses SSL/TLS certificates. What is the MOST secure way to ensure that the connection is encrypted?

A.Configure the EC2 instance to use a self-signed certificate for SSL connections.
B.Enable encryption at rest on the RDS instance to automatically encrypt in-transit traffic.
C.Download the RDS CA certificate to the EC2 instance and configure the database client to use SSL and verify the certificate.
D.Create an IAM policy that requires SSL connections to the RDS endpoint.
AnswerC

Configuring the client with SSL and the downloaded RDS CA certificate enables full certificate verification, authenticating the database endpoint and preventing man-in-the-middle interception. Encryption alone without verification would leave the connection vulnerable, so this satisfies the requirement for the most secure encrypted connection.

Why this answer

Option C is correct because it ensures both encryption and server authentication. Downloading the RDS CA certificate (the trusted root for the RDS instance's server certificate) and configuring the client to verify it prevents man-in-the-middle attacks by confirming the RDS endpoint's identity. Simply enabling SSL without verification (as in other options) leaves the connection vulnerable to spoofing, so this is the most secure approach.

Exam trap

SCS-C02 often tests the misconception that enabling encryption at rest or using an IAM policy alone secures data in transit, when in fact client-side certificate verification is required for true security.

How to eliminate wrong answers

Option A is wrong because using a self-signed certificate on the EC2 instance does not validate the RDS server's certificate; it would either fail the handshake or require disabling verification, defeating the purpose. Option B is wrong because encryption at rest (e.g., RDS storage encryption) has no effect on data in transit; it only protects data on disk. Option D is wrong because an IAM policy can enforce that SSL be used (e.g., via rds:RequireSSL), but it does not configure the client to verify the server certificate, so it does not provide authentication and is not the most secure method.

72
MCQeasy

A company wants to ensure that data at rest in Amazon EBS volumes is encrypted. What is the simplest way to achieve this?

A.Enable EBS encryption by default in the AWS account.
B.Use AWS KMS to create a custom key and attach it to each volume.
C.Encrypt each volume manually using the AWS Management Console.
D.Use an operating system-level encryption tool like LUKS.
AnswerA

Enabling EBS encryption by default at the account or Region level is the simplest, AWS-native way to enforce encryption for all new EBS volumes. No per-volume configuration is required: every newly created volume and any snapshot copied from it is automatically encrypted with the account's default KMS key (AWS-managed or customer-managed). This setting does not retroactively encrypt existing unencrypted volumes, but it ensures all future data-at-rest is protected across the account.

Why this answer

The simplest way to ensure that data at rest in Amazon EBS volumes is encrypted is to enable EBS encryption by default in the AWS account. This setting automatically encrypts all new EBS volumes created in the account, using the default KMS key for EBS encryption. It eliminates the need to manually encrypt each volume or attach custom KMS keys.

Other methods are more manual and do not provide the same level of automation.

Exam trap

SCS-C02 often tests the simplest way to enforce EBS encryption, and candidates may choose manual encryption or custom KMS keys, overlooking the account-level default encryption setting.

How to eliminate wrong answers

Option B is wrong because using a custom KMS key for each volume is manual and does not ensure all volumes are encrypted by default. Option C is wrong because encrypting each volume manually is error-prone and not scalable. Option D is wrong because OS-level encryption like LUKS does not encrypt the EBS volume itself; it encrypts data within the instance, but the volume remains unencrypted at the EBS layer, and snapshots would not be encrypted.

73
MCQhard

Refer to the exhibit. A security engineer runs the AWS CLI command shown and receives an AccessDenied error. The IAM user Alice has a policy that grants kms:Decrypt on all resources. What is the most likely cause of the error?

A.The KMS key policy does not grant kms:Decrypt to the IAM user Alice.
B.The IAM user policy does not allow kms:Decrypt.
C.The command uses the wrong key ID.
D.The ciphertext blob is corrupted.
AnswerA

KMS authorises access through both the key policy and IAM policies. If the key policy does not grant kms:Decrypt to Alice, the request is denied regardless of her identity-based policy, making the key policy the most likely cause.

Why this answer

AWS KMS enforces a two-part authorization model: the caller must be allowed by both the identity-based IAM policy and the KMS key policy. Even though Alice's IAM policy grants kms:Decrypt on all resources, the key policy must also grant her (or her account with delegation) access to that key. If the key policy does not permit Alice, the request is denied, which is the most likely cause of the AccessDenied error.

Exam trap

SCS-C02 often tests the KMS dual-authorization requirement; candidates assume an IAM allow is sufficient and forget that the key policy must also grant access, which is the classic cause of AccessDenied on kms:Decrypt.

How to eliminate wrong answers

Option B is wrong because the scenario explicitly states the IAM user policy grants kms:Decrypt on all resources, so the identity policy is not the blocker. Option C is wrong because using the wrong key ID would typically produce a NotFoundException or a different error, and the scenario implies the correct key is referenced. Option D is wrong because a corrupted ciphertext blob would produce an InvalidCiphertextException or decryption failure, not an AccessDenied authorization error.

74
Multi-Selectmedium

A company is designing a data protection strategy for its Amazon S3 buckets. Which TWO actions can help protect data from accidental deletion or overwrite?

Select 2 answers
A.Enable MFA Delete on the bucket.
B.Enable Cross-Region Replication.
C.Enable default encryption.
D.Enable versioning on the bucket.
E.Set a lifecycle policy to expire objects.
AnswersA, D

MFA Delete is a bucket-level feature that, when enabled alongside versioning, requires a valid multi-factor authentication code before S3 will permanently delete an object version or change the versioning state. Even if an IAM policy grants s3:DeleteObject or s3:DeleteObjectVersion, the API call fails unless the x-amz-mfa header contains a valid code, adding an independent security layer. This specifically prevents accidental or malicious deletion by requiring physical possession of an MFA device, making it a direct and powerful control for data protection.

Why this answer

Option A (Enable MFA Delete on the bucket) is correct because MFA Delete requires multi-factor authentication to permanently delete an object version or to suspend or re-enable versioning, adding a strong safeguard against accidental or malicious deletion. Option D (Enable versioning on the bucket) is correct because versioning keeps multiple variants of an object in the same bucket, so an overwrite creates a new version and a delete only adds a delete marker, allowing the prior version to be restored. Together, versioning preserves prior object states and MFA Delete protects those versions from being permanently removed.

Option B (Cross-Region Replication) is not correct here because it copies objects to another bucket for durability and compliance, but it does not by itself prevent deletion or overwrite in the source bucket. Option C (default encryption) protects data confidentiality at rest but does not stop deletion or overwrite. Option E (a lifecycle policy to expire objects) actually deletes objects, which is the opposite of protecting against accidental deletion.

Exam trap

SCS-C02 often tests whether candidates confuse durability/replication features with deletion-protection features — Cross-Region Replication and encryption are distractors because they do not prevent deletion or overwrite.

75
MCQeasy

A company needs to securely store database credentials for a legacy application running on Amazon EC2. The credentials are currently hardcoded in the application code. Which service should be used to rotate and retrieve secrets automatically?

A.AWS Systems Manager Parameter Store with a SecureString parameter.
B.AWS Key Management Service (KMS).
C.AWS Secrets Manager.
D.AWS CloudHSM.
AnswerC

AWS Secrets Manager is purpose-built for this scenario, offering secure storage, fine-grained access policies, and automatic credential rotation via built-in integrations with services like Amazon RDS and Redshift. It also natively supports secret versioning and schedule-based rotation using Lambda, so database credentials can be refreshed without application downtime or manual intervention.

Why this answer

AWS Secrets Manager is purpose-built for storing, rotating, and retrieving secrets such as database credentials. It natively supports automatic rotation via Lambda functions and provides fine-grained access control using IAM and KMS. The legacy application can retrieve credentials programmatically using the Secrets Manager API or SDK, eliminating hardcoded credentials.

Exam trap

SCS-C02 often tests the distinction between Secrets Manager and Parameter Store, where candidates incorrectly assume Parameter Store's SecureString provides automatic rotation, but only Secrets Manager offers native rotation for database credentials.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store with SecureString can store encrypted parameters but does not provide built-in automatic rotation for database credentials; rotation must be implemented manually. Option B is wrong because AWS KMS is a key management service for encryption keys, not a secrets store; it cannot store or rotate database credentials. Option D is wrong because AWS CloudHSM is a hardware security module for dedicated key storage and cryptographic operations, not a secrets management service with rotation capabilities.

Page 1 of 3 · 176 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Data Protection questions.