Courseiva

SCS-C02 · topic practice

Data Protection practice questions

Data Protection covers encryption at rest and in transit, KMS key policies and grants, ACM certificate management, S3 bucket policies and Object Lock, and Secrets Manager rotation. SCS-C02 tests these through scenario questions: choosing between SSE-KMS and SSE-S3, troubleshooting AccessDenied from key policies, enforcing TLS with aws:SecureTransport, and designing cross-account key access.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Data Protection

What the exam tests

What to know about Data Protection

Choose and troubleshoot SSE-KMS vs SSE-S3, KMS key policies and grants, ACM certificates, S3 Object Lock, and Secrets Manager rotation. Most critical: get KMS key policies and IAM permissions right, since AccessDenied errors usually stem from key policy gaps.

Selecting SSE-S3, SSE-KMS, or DSSE-KMS for S3 objects based on audit and key control needs

Writing KMS key policies and grants that permit cross-account decrypt without wildcard principals

Enforcing TLS-only access using aws:SecureTransport conditions in S3 and IAM policies

Configuring Secrets Manager automatic rotation with Lambda and KMS-encrypted secret values

Watch out for

Common Data Protection exam traps

  • ▸Assuming an IAM policy granting kms:Decrypt is enough; the KMS key policy must also allow the principal.
  • ▸Confusing SSE-KMS bucket default encryption with per-object encryption, missing that existing objects stay unencrypted.
  • ▸Forgetting that KMS grants are needed for temporary cross-account access when key policy edits are impractical.

Practice set

Data Protection questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full Data Protection explanation →

A company stores sensitive data in Amazon S3 and wants to ensure that all objects are encrypted at rest. The security team has enabled default encryption on the S3 bucket using SSE-S3. However, an audit reveals that some objects are stored with SSE-KMS. How can the company enforce that only SSE-S3 is used for all future uploads, while still allowing existing SSE-KMS objects to be read?

A startup is building a web application on AWS and needs to protect sensitive customer data at rest in an Amazon RDS for MySQL database. The compliance team requires that the encryption keys be managed by the company's on-premises hardware security module (HSM) and be rotated every 6 months. Which solution should the startup use?

A company wants to enforce encryption in transit for all data transferred between its Amazon EC2 instances and an Application Load Balancer (ALB). The company uses AWS Certificate Manager (ACM) to provision TLS certificates. Which TWO actions should the company take? (Choose TWO.)

Question 4mediummultiple choice
Read the full Data Protection explanation →

A company uses S3 to store sensitive customer data. The security team requires that all objects uploaded to S3 be encrypted at rest using server-side encryption with AWS KMS managed keys (SSE-KMS). A developer reports that some objects are being stored unencrypted. What is the MOST effective way to enforce this requirement?

Question 5mediummultiple choice
Read the full Data Protection explanation →

A company uses AWS KMS to encrypt EBS volumes. The security team wants to ensure that when an EC2 instance is launched, the attached EBS volumes are always encrypted using a specific customer managed key. Which action will enforce this?

A company stores sensitive data in an S3 bucket with versioning enabled. They want to ensure that objects are encrypted at rest using SSE-KMS. A security audit reveals that some older object versions are encrypted with SSE-S3. What is the MOST efficient way to re-encrypt those older versions with SSE-KMS?

A company wants to protect data at rest for an Amazon S3 bucket that contains sensitive data. Which combination of actions provides the MOST comprehensive protection? (Choose two.)

Question 8mediummultiple choice
Read the full Data Protection explanation →

A company uses S3 to store confidential documents. They want to ensure that objects are encrypted at rest using customer-provided encryption keys (SSE-C). Which header must be included in every PUT request?

A company has a compliance requirement to encrypt all data in Amazon S3 using keys that are managed by the company's internal security team. The keys must be stored in a hardware security module (HSM) that is FIPS 140-2 Level 3 certified. Which AWS service should be used?

Question 10hardmultiple choice
Read the full Data Protection explanation →

A company uses Amazon S3 to store sensitive documents. They must ensure that all objects are encrypted at rest and that any attempt to upload an unencrypted object is denied. Which S3 bucket policy statement achieves this?

A company is designing a data protection strategy for sensitive customer data stored in Amazon S3. Which TWO actions should be taken to protect the data from accidental deletion?

A company is using AWS KMS to encrypt data in Amazon S3 and Amazon RDS. Which THREE practices should be followed to ensure the security of the KMS keys?

Question 13mediummultiple choice
Read the full Data Protection explanation →

A security engineer inspects two KMS keys. Which key can be used for envelope encryption with automatic key rotation?

Network Topology
key-id 1234abcd-12ab-34cd-56ef-1234567890ab$ aws kms describe-keykey-id 2345bcde-23bc-45de-67fg-2345678901bcRefer to the exhibit.$ aws kms list-keys"Keys": [{"KeyId": "1234abcd-12ab-34cd-56ef-1234567890ab"},{"KeyId": "2345bcde-23bc-45de-67fg-2345678901bc"}"KeyMetadata": {"KeyId": "1234abcd-12ab-34cd-56ef-1234567890ab","KeyManager": "AWS","KeyState": "Enabled","Origin": "AWS_KMS","KeyRotationEnabled": true,"CreationDate": "2023-01-15T10:00:00+00:00""KeyId": "2345bcde-23bc-45de-67fg-2345678901bc","KeyManager": "CUSTOMER","KeyRotationEnabled": false,"CreationDate": "2023-06-20T10:00:00+00:00"
Question 14mediummultiple choice
Read the full Data Protection explanation →

A company uses AWS KMS to encrypt data in Amazon S3. The security team wants to enforce that all S3 PUT requests include a specific encryption context key. Which S3 bucket policy condition key should be used?

Question 15mediummultiple choice
Read the full Data Protection explanation →

A company stores sensitive data in an S3 bucket. The security team wants to ensure that all objects are encrypted at rest using server-side encryption with AWS KMS managed keys (SSE-KMS). An application writes objects to the bucket but sometimes fails because the encryption key is not found. What is the MOST likely cause?

Which TWO actions can help protect data at rest in Amazon EBS volumes? (Choose 2.)

Which THREE practices are recommended for managing encryption keys in AWS KMS? (Choose 3.)

Question 18mediummultiple choice
Read the full Data Protection explanation →

Refer to the exhibit. A security engineer reviews the key policy of an AWS KMS customer managed key. The AppRole role is used by an application to encrypt and decrypt data. However, the application is unable to decrypt data. What is the MOST likely cause?

Network Topology
aws kms get-key-policykey-id 1234abcd-12ab-34cd-56ef-1234567890abpolicy-name defaultRefer to the exhibit.```"Version": "2012-10-17","Id": "key-consolepolicy-3","Statement": ["Sid": "Enable IAM User Permissions","Effect": "Allow","Principal": {"AWS": "arn:aws:iam::111122223333:root"},"Action": "kms:*","Resource": "*""AWS": "arn:aws:iam::111122223333:role/Admin""Action": ["kms:Create*","kms:Describe*","kms:Enable*","kms:List*","kms:Put*","kms:Update*","kms:Revoke*","kms:Disable*","kms:Get*","kms:Delete*","kms:ScheduleKeyDeletion"],"AWS": "arn:aws:iam::111122223333:role/AppRole""kms:Encrypt","kms:Decrypt","kms:ReEncrypt*","kms:GenerateDataKey*","kms:DescribeKey"
Question 19hardmultiple choice
Read the full Data Protection explanation →

A company is migrating on-premises data to AWS using AWS Snowball Edge. The data must be encrypted in transit and at rest. Which combination of steps should be taken?

Question 20easymultiple choice
Read the full Data Protection explanation →

A company needs to protect data stored in S3 from accidental deletion by users. Which S3 feature should be used?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Data Protection sessions

Start a Data Protection only practice session

Every question in these sessions is drawn from the Data Protection domain — nothing else.

Related practice questions

Related SCS-C02 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SCS-C02 exam test about Data Protection?
Choose and troubleshoot SSE-KMS vs SSE-S3, KMS key policies and grants, ACM certificates, S3 Object Lock, and Secrets Manager rotation. Most critical: get KMS key policies and IAM permissions right, since AccessDenied errors usually stem from key policy gaps.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Data Protection questions in a focused session?
Yes — the session launcher on this page draws every question from the Data Protection domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SCS-C02 topics?
Use the topic links above to move to related areas, or go back to the SCS-C02 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SCS-C02 exam covers. They are not copied from any real exam or dump site.