Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

Network Topology
aws kms encryptkey-id 1234abcd-12ab-34cd-56ef-1234567890abplaintext fileb://secret.txtoutput textquery CiphertextBlobRefer to the exhibit.```

Refer to the exhibit. A security engineer runs the above AWS CLI command to encrypt a secret file. The command succeeds and returns a base64-encoded ciphertext. Which of the following statements is correct?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The command returns a base64-encoded ciphertext that can be decrypted with the same KMS key.

The command encrypts the plaintext file using the specified KMS key and returns the ciphertext as base64-encoded output. Option A is wrong because the command does not specify an encryption context; it's optional. Option B is wrong because the command uses fileb:// which reads binary data; it will succeed if the file exists. Option D is wrong because the output is the ciphertext, not a data key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The command returns a plaintext data key and an encrypted copy.

    Why it's wrong here

    The Encrypt API does not return a plaintext data key; it takes plaintext and returns only ciphertext. Returning both a plaintext key and an encrypted copy is the defining behavior of GenerateDataKey, which creates a symmetric data key for use outside KMS. Therefore, this option confuses the Encrypt operation with a different KMS API and is incorrect.

  • ✗

    The command will fail because fileb:// is not a valid prefix.

    Why it's wrong here

    fileb:// is a valid AWS CLI prefix for reading a file as raw binary data, as opposed to file:// which reads it as UTF-8 text. The kms encrypt command accepts binary plaintext input, so fileb:// is the appropriate prefix to use when passing a local file. The command will not fail because of this prefix; it is the standard way to provide binary input to AWS CLI commands.

  • ✓

    The command returns a base64-encoded ciphertext that can be decrypted with the same KMS key.

    Why this is correct

    The kms encrypt API returns a CiphertextBlob, and the AWS CLI base64-encodes this binary field in its JSON output. The ciphertext is encrypted under the customer master key specified in the command, so the same KMS key can decrypt it by calling kms decrypt after base64-decoding the blob. This matches the actual behavior of the command and is therefore the correct answer.

  • ✗

    The command will fail because encryption context is required.

    Why it's wrong here

    Encryption context is optional for the KMS Encrypt API; it is metadata that KMS cryptographically binds to the ciphertext but is not required to be supplied. If you omit it, the encrypt call succeeds, although you must then omit it during decryption as well because the context must match exactly. A KMS key policy could require a specific encryption context, but by default the API does not enforce one, so this option incorrectly claims the command will fail.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.