Courseiva

CCNA Data Protection Questions

75 of 176 questions · Page 2/3 · Data Protection topic · Answers revealed

76
MCQeasy

A company uses AWS Secrets Manager to store database credentials. They need to rotate the secrets automatically every 30 days. Which rotation strategy should they use?

A.Use AWS Systems Manager Parameter Store to rotate the secret.
B.Manually update the secret every 30 days.
C.Enable automatic rotation in Secrets Manager and specify a Lambda rotation function.
D.Use an AWS Config rule to trigger rotation.
AnswerC

Enabling automatic rotation in AWS Secrets Manager and specifying a Lambda rotation function is the correct approach. Secrets Manager invokes the Lambda function on a configurable schedule (e.g., every 30 days), and the function follows the rotation protocol—creating a new credential, updating the database user/password, and storing the new value as a version of the secret. This allows applications to automatically retrieve the new credential via the secret ARN while keeping the database credential synchronized, and it supports multi-user or single-user rotation strategies.

Why this answer

AWS Secrets Manager natively supports automatic rotation of secrets, and you must specify an AWS Lambda function to perform the rotation logic (e.g., updating the database password and storing the new secret). This ensures the secret is rotated on a schedule (every 30 days) without manual intervention, meeting the requirement for automated rotation.

Exam trap

The trap here is that candidates may confuse AWS Systems Manager Parameter Store with Secrets Manager, thinking Parameter Store can also rotate secrets automatically, or they may incorrectly assume AWS Config rules can schedule rotations, when in fact only Secrets Manager with a Lambda function provides native automatic rotation.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store does not have built-in automatic rotation capabilities; it is a parameter store, not a secrets rotation service, and would require custom automation to rotate secrets. Option B is wrong because manually updating the secret every 30 days is not automated and defeats the purpose of using Secrets Manager for rotation; it introduces human error and operational overhead. Option D is wrong because AWS Config rules are used for compliance evaluation and remediation, not for scheduling or executing secret rotation; they can trigger a Lambda function for remediation but are not designed as a rotation scheduler.

77
MCQhard

Refer to the exhibit. A security engineer is troubleshooting a decryption failure. The command uses the AWS CLI to decrypt a file. The decryption fails with an 'AccessDeniedException' error. The IAM user has the following policy attached: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "kms:Decrypt", "Resource": "*" } ] } What is the most likely cause of the failure?

A.The KMS key policy does not grant the IAM user decrypt permission
B.The IAM user does not have permission to call kms:Decrypt on the specific key
C.The ciphertext blob is not valid
D.The IAM user is not authorized to use the AWS CLI
AnswerA

The KMS key policy is the resource policy attached to a KMS key and is the authoritative control for access. In AWS KMS, an IAM policy alone does not grant permission; the key policy must explicitly allow the IAM user (or allow the account's IAM policies to take effect) for kms:Decrypt. Because the key policy here lacks such an allowance, the request is denied with AccessDenied even if the IAM identity policy appears permissive. Therefore, the missing key-policy grant for this user is the direct cause of the failure.

Why this answer

KMS decryption requires permission from BOTH the IAM identity-based policy AND the KMS key policy. Even though the IAM policy grants kms:Decrypt on '*', the key policy must also explicitly allow the IAM user (or their account with the right conditions) to use the key. If the key policy does not grant access, the request fails with AccessDeniedException regardless of the IAM policy.

Exam trap

SCS-C02 often tests the KMS dual-authorization model, tricking candidates into assuming that a wildcard IAM policy alone is sufficient — the key policy is the missing piece that causes AccessDeniedException.

How to eliminate wrong answers

Option B is wrong because the IAM policy already grants kms:Decrypt on Resource '*', so the IAM side is not the blocker — the missing piece is the key policy. Option C is wrong because an invalid ciphertext blob would produce an InvalidCiphertextException, not AccessDeniedException. Option D is wrong because AWS CLI authorization is governed by IAM permissions, not a separate CLI-level authorization — if the CLI can authenticate, it can call any API the IAM principal is permitted to call.

78
MCQhard

A security engineer applies the bucket policy shown in the exhibit to an S3 bucket. What is the effect of this policy?

A.Allows uploads only if they use SSE-S3.
B.Allows uploads without encryption.
C.Allows uploads with any server-side encryption.
D.Allows uploads only if they use SSE-KMS.
AnswerD

The policy's `s3:PutObject` statement carries a `StringNotEquals` condition on `s3:x-amz-server-side-encryption` with value `aws:kms`, so any upload lacking the SSE-KMS header is explicitly denied. This satisfies the stem's constraint by permitting only requests specifying SSE-KMS encryption, blocking SSE-S3 and unencrypted writes.

Why this answer

The bucket policy shown in the exhibit uses a Deny effect with a condition that checks whether the s3:x-amz-server-side-encryption header does not equal aws:kms, which means any upload request that does not specify SSE-KMS encryption is denied. Therefore, the policy effectively allows uploads only if they use SSE-KMS. This is a common pattern to enforce encryption at rest with a specific KMS key type.

Exam trap

SCS-C02 often tests the difference between SSE-S3 (AES-256, AWS-managed keys) and SSE-KMS (AWS KMS keys) in bucket policy conditions — candidates see 'server-side encryption' and incorrectly assume any encryption type satisfies the policy, missing the specific aws:kms value in the condition.

How to eliminate wrong answers

Option A is wrong because the policy condition specifically checks for aws:kms, not aws:s3 (which is SSE-S3), so SSE-S3 uploads would be denied. Option B is wrong because the policy explicitly denies uploads without the required encryption header, so unencrypted uploads are blocked. Option C is wrong because the condition uses StringNotEquals with aws:kms, meaning only SSE-KMS satisfies the condition — other encryption types like SSE-S3 or SSE-C would fail the condition and be denied.

79
Multi-Selecteasy

Which TWO of the following are valid options for encrypting data at rest in Amazon EBS? (Choose two.)

Select 2 answers
A.Enable EBS encryption by default using the AWS managed key for EBS.
B.Use a customer managed KMS key.
C.Use an encryption script on the EC2 instance to encrypt the volume.
D.Use AWS CloudHSM to generate and store the encryption key.
E.Use S3 server-side encryption to encrypt the EBS snapshot.
AnswersA, B

Enabling EBS encryption by default causes all newly created EBS volumes and snapshots to be encrypted automatically. When no custom key is specified, AWS uses the AWS managed key with alias 'aws/ebs' to perform encryption, which is transparent and requires no additional configuration. This satisfies encryption-at-rest requirements with minimal operational overhead and is the simplest valid option.

Why this answer

Option A is correct because Amazon EBS supports account-level and Region-level encryption by default, which automatically encrypts new volumes and snapshots using the AWS managed key for EBS (aws/ebs) unless you specify a different key. Option B is correct because EBS encryption can be configured to use a customer managed KMS key, giving you control over key policies, rotation, and grants while still using the native EBS/KMS encryption mechanism. Option C is not a valid EBS at-rest encryption option because running an encryption script inside the EC2 instance is application-level or OS-level encryption, not native EBS volume encryption.

Option D is not correct because CloudHSM is a separate HSM service and is not the mechanism used to generate or store EBS encryption keys; EBS encryption keys are managed through AWS KMS. Option E is not correct because S3 server-side encryption protects objects stored in S3, not EBS volumes or EBS snapshots.

Exam trap

SCS-C02 often tests the difference between native AWS encryption mechanisms and application-level or unrelated service encryption; candidates may pick CloudHSM or S3 encryption thinking they apply to EBS, but only KMS-based options are valid for EBS at rest.

80
MCQhard

A financial services company is designing a data protection strategy for its DynamoDB table containing sensitive customer data. The table has a global secondary index (GSI). The company needs to encrypt the data at rest using a customer managed key (CMK) that is rotated annually. Which solution meets these requirements?

A.Create the table with default encryption, then update the table to use a CMK and enable automatic rotation
B.Create the table without encryption, then enable encryption on the table and GSI separately using a CMK
C.Create the table with an AWS managed key and use AWS KMS automatic rotation
D.Create the table with a customer managed key (CMK) and enable automatic key rotation
AnswerD

A customer managed CMK is the correct choice because the customer controls the key, including its rotation schedule, access policies, and auditability, which meets financial services compliance demands. When you create a DynamoDB table with a customer managed CMK and enable automatic key rotation, DynamoDB uses that key to encrypt the base table and all GSIs automatically, as GSIs inherit the table's encryption settings. This provides unified, customer-controlled encryption with rotation, fully satisfying the requirement.

Why this answer

DynamoDB supports encryption at rest using AWS KMS. When a table is created, you must specify whether to use a default AWS managed key or a customer managed key (CMK). The global secondary index (GSI) inherits the encryption settings from the base table and cannot have separate encryption settings.

Option D is correct because you can create the table with a CMK and enable automatic key rotation on that CMK. Option A is incorrect because you cannot change the encryption key of an existing DynamoDB table; encryption settings must be specified at creation. Option B is incorrect because DynamoDB tables always have encryption enabled by default (you cannot create a table without encryption), and you cannot enable encryption separately on the GSI.

Option C is incorrect because the requirement specifies a customer managed key (CMK), not an AWS managed key; while AWS managed keys have automatic rotation by default, they do not provide customer control over the key.

81
MCQmedium

A company wants to protect data in transit between its on-premises network and Amazon VPC using IPsec VPN. Which AWS service should be used to establish this VPN connection?

A.AWS Client VPN
B.AWS Site-to-Site VPN
C.AWS Transit Gateway
D.AWS Direct Connect
AnswerB

AWS Site-to-Site VPN creates encrypted IPsec tunnels between an on-premises customer gateway device and an AWS virtual private gateway or transit gateway attachment. It automatically provisions two tunnels for high availability, encrypts traffic as it traverses the public internet, and supports dynamic BGP or static routing. This directly satisfies the requirement to protect data in transit between the on-premises network and the VPC.

Why this answer

AWS Site-to-Site VPN is the service used to establish an IPsec VPN connection between an on-premises network and an Amazon VPC. It creates a secure tunnel over the internet using IPsec, terminating on a Virtual Private Gateway (VGW) or Transit Gateway on the AWS side and a Customer Gateway on the on-premises side.

Exam trap

SCS-C02 often tests the distinction between Site-to-Site VPN (network-to-network IPsec) and Client VPN (user-to-network) — the trap is selecting Client VPN or Transit Gateway when the requirement is specifically an IPsec VPN between an on-premises network and a VPC.

How to eliminate wrong answers

Option A is wrong because AWS Client VPN is a managed client-based VPN service for individual remote users to connect to AWS or on-premises networks, not for site-to-site connectivity between networks. Option C is wrong because AWS Transit Gateway is a network transit hub that can attach VPCs and VPNs, but it is not the service that establishes the IPsec VPN connection itself — it can be the termination point, but the VPN service is Site-to-Site VPN. Option D is wrong because AWS Direct Connect provides a dedicated private network connection, not an IPsec VPN over the internet.

82
Multi-Selectmedium

A company is designing a data protection strategy for Amazon EBS volumes. Which TWO practices should be implemented? (Choose TWO.)

Select 2 answers
A.Enable encryption by default for new EBS volumes
B.Use S3 Object Lock to prevent deletion of snapshots
C.Enable automated backups for Amazon RDS
D.Take regular snapshots of EBS volumes and store them in a different region
E.Use EBS multi-attach for high availability
AnswersA, D

Enabling encryption by default for new EBS volumes is a foundational data-at-rest protection control because it automatically encrypts the underlying volume and its snapshots with an AWS KMS key, without requiring per-volume configuration. This prevents raw storage from being accessed if an unauthorized party gains access to the physical media, and it also ensures that any future snapshots derived from these volumes inherit the same encryption, which is mandatory for many compliance frameworks.

Why this answer

Option A is correct because enabling EBS encryption by default ensures that all newly created EBS volumes in the account/Region are automatically encrypted at rest using AWS KMS keys, protecting data without relying on manual per-volume configuration. Option D is correct because EBS snapshots are incremental, point-in-time backups stored in Amazon S3, and copying them to a different Region provides cross-Region durability and disaster recovery against Regional failures or accidental deletion. Option B is incorrect because S3 Object Lock applies to objects in S3 buckets, not to EBS snapshots, which are managed through EBS snapshot APIs and lifecycle policies.

Option C is incorrect because automated backups for Amazon RDS protect RDS databases, not EBS volumes, so it does not address the EBS data protection requirement. Option E is incorrect because EBS Multi-Attach only allows a single io1/io2 volume to be attached to multiple Nitro-based EC2 instances in the same AZ for concurrent access, and it does not provide backup or data protection.

Exam trap

SCS-C02 often tests the misconception that S3 Object Lock can be used to protect EBS snapshots, confusing S3 features with EBS capabilities, or that EBS multi-attach provides high availability, when it is actually for concurrent access in clustered applications.

83
Multi-Selectmedium

Which TWO AWS services can be used to monitor and audit data access patterns to Amazon S3 buckets? (Choose 2.)

Select 2 answers
A.AWS Config
B.AWS CloudWatch
C.AWS CloudTrail
D.Amazon S3 Server Access Logs
E.AWS Trusted Advisor
AnswersC, D

AWS CloudTrail records S3 data events such as GetObject and PutObject, capturing the identity, source IP, timestamp and request details for each object-level API call. This satisfies the requirement to audit who accessed which objects, provided data events are explicitly enabled on the trail.

Why this answer

AWS CloudTrail (C) is correct because it records S3 data-plane API calls such as GetObject and PutObject when data events are enabled, providing an audit trail of who accessed which objects and when. Amazon S3 Server Access Logs (D) is correct because S3 can deliver detailed, per-request access records (requester, bucket, operation, HTTP status, bytes) directly to a target bucket for auditing access patterns. AWS Config (A) tracks resource configuration changes and compliance, not object-level data access patterns.

AWS CloudWatch (B) provides metrics, logs, and alarms but does not natively audit S3 object access requests. AWS Trusted Advisor (E) offers best-practice checks and recommendations, not access auditing.

Exam trap

The trap here is that candidates often confuse AWS Config (which checks configuration compliance) with CloudTrail (which records API activity), or they overlook that S3 Server Access Logs are a separate, native logging feature distinct from CloudTrail.

84
MCQeasy

A company wants to ensure that data stored in Amazon S3 is encrypted at rest using keys managed by AWS. Which encryption option should they choose?

A.Client-side encryption.
B.Server-side encryption with AWS KMS (SSE-KMS).
C.Server-side encryption with customer-provided keys (SSE-C).
D.Server-side encryption with S3 managed keys (SSE-S3).
AnswerD

SSE-S3 uses a multi-layer envelope encryption scheme in which Amazon S3 creates a unique data key for each object and encrypts that data key with a S3-owned master key that AWS automatically rotates. The customer needs no key material, no KMS configuration, and no key lifecycle management, making this the straightforward option for delegating key management entirely to AWS. It is the only option listed that relies purely on AWS-managed keys with no customer-controlled key configuration.

Why this answer

SSE-S3 uses AES-256 encryption keys managed entirely by AWS, fulfilling the requirement for encryption at rest with AWS-managed keys. When you upload an object, S3 encrypts it before writing to disk and decrypts it when you access it, all without any customer action or key management overhead.

Exam trap

The trap here is that candidates often confuse SSE-KMS as 'AWS-managed' because KMS can use AWS managed keys, but the question specifically requires keys managed solely by AWS without any customer involvement, which only SSE-S3 provides.

How to eliminate wrong answers

Option A is wrong because client-side encryption requires the customer to manage keys and encrypt data before uploading, which does not meet the requirement for AWS-managed keys. Option B is wrong because SSE-KMS uses AWS KMS keys that are customer-managed (or AWS-managed but with customer control over key policies and rotation), not purely AWS-managed keys as specified. Option C is wrong because SSE-C requires the customer to provide and manage their own encryption keys, which contradicts the requirement for keys managed by AWS.

85
MCQmedium

A company runs a web application on Amazon EC2 behind an Application Load Balancer (ALB). The application handles payment card information (PCI) and must comply with PCI DSS. The security team wants to ensure that all data in transit between the client and the ALB is encrypted using TLS 1.2 or higher. The ALB currently uses a default certificate from AWS Certificate Manager (ACM) that was issued by Amazon. The compliance team has flagged that the certificate must be issued by a public Certificate Authority (CA) that is trusted by major browsers. The company wants to minimize operational overhead. What should the security team do?

A.Use AWS CloudHSM to generate a certificate and import it into ACM
B.Configure CloudFront in front of the ALB and use a CloudFront default certificate
C.Generate a self-signed certificate on the EC2 instance and upload it to ACM, then associate it with the ALB
D.Request a public certificate from ACM and associate it with the ALB
AnswerD

Requesting a public certificate from AWS Certificate Manager is the correct, fully managed way to implement HTTPS on an Application Load Balancer. ACM's public certificates are issued by trusted CAs (such as Amazon Trust Services), are free of charge, and are automatically renewed as long as you maintain the required DNS validation or email validation records. After ACM validates your domain, you simply attach the certificate to the ALB's HTTPS listener, and the ALB handles TLS termination. This avoids any self-managed CA infrastructure and is aligned with AWS best practices for securing a web application.

Why this answer

AWS Certificate Manager (ACM) can issue public certificates that are signed by Amazon's public CA, which is trusted by all major browsers and operating systems. Requesting a public certificate in ACM and associating it with the ALB listener satisfies the PCI DSS requirement for TLS 1.2+ encryption with a publicly trusted CA, while ACM handles renewal automatically — minimising operational overhead. This is the canonical AWS-recommended approach for ALB TLS termination.

Exam trap

The trap is overcomplicating the solution with CloudHSM or self-signed certs — candidates forget that ACM-issued public certificates are already signed by a browser-trusted public CA, making them the lowest-overhead compliant choice.

How to eliminate wrong answers

Option A is wrong because CloudHSM is for generating and storing private keys in a dedicated hardware security module; using it to create a certificate and import it into ACM adds significant operational overhead and is unnecessary when ACM can issue a trusted public cert directly. Option B is wrong because CloudFront default certificates only work for CloudFront distributions on the `*.cloudfront.net` domain and cannot be used for a custom domain or to secure the ALB's own endpoint — it also adds an unnecessary layer. Option C is wrong because a self-signed certificate is not trusted by browsers or public CAs, directly violating the compliance requirement, and ACM does not allow importing self-signed certs for public trust purposes.

86
MCQmedium

A security engineer needs to audit all access to a KMS customer managed key. Which AWS service should be used?

A.AWS Config
B.VPC Flow Logs
C.Amazon CloudWatch Logs
D.AWS CloudTrail
AnswerD

AWS CloudTrail records all KMS API requests as audit events, including both management-plane actions (such as CreateKey, EnableKeyRotation, and DescribeCustomKeyStores) and data-plane operations like Encrypt, Decrypt, and GenerateDataKey. Each CloudTrail event captures the caller's IAM identity, source IP address, key ID, request parameters, and timestamp, and can be delivered to Amazon S3 or CloudWatch Logs for long-term retention and analysis. CloudTrail is therefore the authoritative service for auditing all access to a KMS custom key store or the keys associated with it.

Why this answer

AWS CloudTrail records every API call made to KMS, including Encrypt, Decrypt, GenerateDataKey, CreateKey, and key policy changes, capturing the caller identity, source IP, timestamp, and request parameters. This makes CloudTrail the authoritative service for auditing KMS key usage and access.

Exam trap

The trap is confusing configuration auditing (AWS Config) with access auditing (CloudTrail); Config tells you what a resource looks like, CloudTrail tells you who did what to it.

How to eliminate wrong answers

Option A is wrong because AWS Config tracks resource configuration changes and compliance, not individual API-level access events to KMS keys. Option B is wrong because VPC Flow Logs capture IP-level network traffic metadata (source/dest IP, port, protocol), not KMS API calls, which are HTTPS to the KMS endpoint. Option C is wrong because CloudWatch Logs stores log data but does not natively capture KMS API activity unless CloudTrail is configured to deliver to it; CloudWatch alone is not the audit source.

87
MCQeasy

A company wants to automate the detection of sensitive data in an S3 bucket. Which AWS service should be used?

A.Amazon Macie
B.AWS Artifact
C.Amazon Inspector
D.Amazon GuardDuty
AnswerA

Amazon Macie is a fully managed data security service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data stored in S3. It identifies data types such as personally identifiable information (PII), financial data, and credentials, then surfaces findings in dashboards and EventBridge events. For this use case, Macie is correct because it continuously scans and reports on sensitive data without requiring custom tooling or manual inspection.

Why this answer

Amazon Macie uses machine learning to discover and classify sensitive data, making it the correct choice for automated detection of sensitive data in S3. AWS Artifact provides compliance reports, Amazon Inspector assesses vulnerabilities, and Amazon GuardDuty detects threats—none specifically focus on sensitive data detection.

88
MCQeasy

A company is designing a disaster recovery plan for its Amazon RDS for MySQL database. The database must be encrypted at rest. Which approach ensures that the database is encrypted and can be restored in another AWS Region?

A.Enable encryption on the existing DB instance
B.Export the database to Amazon S3 and use S3 cross-Region replication
C.Create a manual snapshot and copy it to another Region with encryption
D.Create a cross-Region read replica with encryption enabled
AnswerD

Creating a cross-Region read replica with encryption enabled gives you a continuously updated, readable copy of the primary database in another AWS Region. RDS automatically replicates changes from the primary using its asynchronous replication engine, and in a disaster you simply promote the replica to a standalone master with a few clicks, minimizing RTO. For encryption, the primary must be encrypted and you specify an AWS KMS key in the destination Region when creating the replica, so the DR copy is encrypted in transit and at rest.

Why this answer

(Create a cross-Region read replica with encryption enabled) is correct because it continuously replicates data to another AWS Region and encryption at rest can be enabled, ensuring both disaster recovery and encryption. Option A is wrong because encryption cannot be enabled on an existing unencrypted DB instance; a new encrypted instance must be created. Option B is wrong because exporting to S3 and using cross-Region replication does not provide a real-time database replica and complicates recovery.

Option C is wrong because while a manual snapshot can be copied to another Region with encryption, it does not provide continuous replication; it is a point-in-time backup, not a disaster recovery solution that minimizes data loss.

89
MCQmedium

A security engineer is configuring a new Amazon RDS for MySQL database. The compliance team requires that all database connections be encrypted in transit. Which configuration ensures this requirement is met?

A.Enable encryption at rest using KMS
B.Enable IAM database authentication
C.Set the 'ssl' parameter to '1' in the DB parameter group
D.Enable the 'require_secure_transport' parameter in the DB parameter group
AnswerD

Setting require_secure_transport to 1 in the custom DB parameter group instructs the MySQL server to reject any connection that does not use a secure transport protocol such as TLS/SSL. This enforces encryption in transit at the server level, meaning clients that request plaintext are refused immediately. It directly addresses the requirement to prevent all unencrypted traffic, regardless of client-side settings.

Why this answer

Setting the 'require_secure_transport' parameter to '1' in the DB parameter group forces all connections to the RDS for MySQL instance to use TLS/SSL encryption. This ensures that data in transit is encrypted, meeting the compliance requirement. The parameter enforces that only encrypted connections are accepted, rejecting any unencrypted attempts.

Exam trap

The trap here is that candidates often confuse enabling SSL support (the 'ssl' parameter) with requiring SSL (the 'require_secure_transport' parameter), thinking that simply enabling SSL on the server forces all clients to use it, but in reality, the server will accept both encrypted and unencrypted connections unless the requirement is explicitly enforced.

How to eliminate wrong answers

Option A is wrong because encryption at rest using KMS protects data stored on disk, not data transmitted over the network, so it does not address encryption in transit. Option B is wrong because IAM database authentication provides authentication using IAM credentials, but it does not enforce or provide encryption of the connection itself; it can be used with or without SSL. Option C is wrong because setting the 'ssl' parameter to '1' enables SSL support on the server, but it does not require clients to use SSL; clients can still connect without encryption, so it does not guarantee all connections are encrypted.

90
MCQhard

A company has an S3 bucket with versioning and MFA Delete enabled. A user attempts to delete an object version using the AWS CLI without MFA. What will happen?

A.The object version is marked for deletion and will be deleted after 30 days.
B.The request fails with an AccessDenied error.
C.The object version is deleted and a delete marker is created.
D.The object version is deleted but not permanently.
AnswerB

The correct behavior is that the request fails with AccessDenied. S3 MFA Delete requires an MFA-authenticated request to permanently delete an object version. Since the request does not include the x-amz-mfa header with a valid MFA code, S3 denies the DeleteObject call. This prevents any deletion, including creation of delete markers.

Why this answer

When MFA Delete is enabled on an S3 bucket, any request to permanently delete an object version or to change the versioning state of the bucket must include a valid MFA token. If a user attempts to delete an object version without MFA, the request fails with an AccessDenied error. This is the expected behavior to protect against accidental or malicious deletions.

Exam trap

SCS-C02 often tests the misconception that MFA Delete applies to all delete operations, but it only applies to deleting specific object versions or changing versioning state; deleting an object without a version ID (creating a delete marker) does not require MFA.

How to eliminate wrong answers

Option A is wrong because there is no automatic deletion after 30 days; MFA Delete does not mark objects for deletion. Option C is wrong because deleting an object version without MFA is not allowed; a delete marker is created only when deleting an object without specifying a version ID, but that is a different operation and still requires MFA if MFA Delete is enabled for version deletion. Option D is wrong because the object version is not deleted at all; the request is denied.

91
MCQmedium

A company uses AWS KMS to encrypt data at rest in Amazon S3. The security team requires that all encryption keys be automatically rotated every year. Which solution meets this requirement?

A.Use an AWS managed key and enable automatic rotation.
B.Use a customer managed key with imported key material and enable automatic rotation.
C.Use a customer managed key and enable automatic rotation with a yearly rotation period.
D.Use an AWS managed key and manually rotate it every year.
AnswerC

A customer managed key provides the administrative control needed to satisfy the requirement, and KMS supports automatic rotation with a configurable period between 90 and 2560 days for symmetric keys generated in KMS. By creating a customer managed key with KMS-generated key material and setting its automatic rotation period to 365 days, the company achieves seamless annual rotation while decrypting data with previous key versions as needed.

Why this answer

Customer managed keys (CMKs) in AWS KMS support automatic rotation with a customizable rotation period, which can be set to 365 days (one year) to meet the security team's requirement. AWS managed keys, on the other hand, have a fixed automatic rotation period of every three years (1095 days) and cannot be adjusted, making them unsuitable for a yearly rotation mandate. By using a CMK with automatic rotation enabled and specifying a rotation period of one year, the company ensures that the encryption key material is rotated annually without manual intervention.

Exam trap

The trap here is that candidates often assume AWS managed keys can be configured for automatic rotation with a custom period, but in reality, AWS managed keys have a fixed three-year rotation schedule and cannot be adjusted, making customer managed keys the only option for yearly rotation.

How to eliminate wrong answers

Option A is wrong because AWS managed keys have a fixed automatic rotation period of approximately three years (1095 days) and do not allow customization to a yearly rotation period. Option B is wrong because customer managed keys with imported key material do not support automatic rotation; AWS KMS cannot rotate key material that was imported from an external source, so the security team would need to manually rotate the key. Option D is wrong because AWS managed keys cannot be manually rotated; they are managed entirely by AWS and do not provide a manual rotation capability, and even if manual rotation were possible, it would not meet the 'automatically rotated' requirement.

92
MCQeasy

A company stores sensitive data in an Amazon S3 bucket. The security team requires that all data in transit between the company's on-premises data center and S3 be encrypted. Which solution meets this requirement?

A.Set up an IPsec VPN connection between the data center and AWS, and access S3 through the VPN.
B.Enable S3 Transfer Acceleration on the bucket.
C.Use HTTPS (TLS) endpoints when uploading objects to S3.
D.Use AWS PrivateLink to create a VPC endpoint for S3.
AnswerC

Using HTTPS (TLS) endpoints for S3 requests encrypts the entire request payload, the headers, and the response in transit between the client and S3. TLS provides confidentiality, integrity, and authentication, preventing eavesdropping and tampering. This is the correct approach because it ensures each object upload is protected end-to-end at the application layer, regardless of network path.

Why this answer

Using HTTPS (TLS) ensures encryption of data in transit between the client and S3. Option A is incorrect because although an IPsec VPN encrypts traffic between the data center and AWS, the data is then decrypted and sent to S3, so it does not guarantee encryption for the entire path unless S3 is accessed via HTTPS as well. Option B is incorrect because S3 Transfer Acceleration speeds up transfers using edge locations but does not provide encryption; HTTPS is still required.

Option D is incorrect because a VPC endpoint for S3 provides private connectivity but does not encrypt traffic; encryption still relies on HTTPS.

93
MCQhard

A company is using AWS KMS to encrypt data in Amazon Redshift. They need to rotate the KMS key annually. Which approach meets the requirement with minimal operational impact?

A.Create a new KMS key each year and update the Redshift cluster to use the new key
B.Use an AWS Lambda function to rotate the key every year
C.Enable automatic key rotation on the KMS key
D.Rotate the key by re-importing key material into an existing KMS key
AnswerC

Enable automatic rotation on the KMS key. AWS KMS automatically rotates the backing key material one year after the key is created and then every year thereafter, while keeping the same key ID and metadata, so Redshift continues to use the key without any reconfiguration. The old key material is retained to decrypt existing ciphertext, ensuring that all data encrypted under prior versions remains accessible. This meets the requirement of key rotation with minimal effort and no application changes.

Why this answer

AWS KMS supports automatic annual key rotation for customer-managed KMS keys. Enabling this feature automatically rotates the key material once per year with no manual intervention, minimal operational overhead, and no impact on the Redshift cluster, which continues to use the same key ID.

Exam trap

The trap here is that candidates may think automatic rotation is not available for KMS keys or that they must manually rotate keys using Lambda or by creating new keys, when in fact KMS provides a simple toggle for annual automatic rotation that requires no additional resources.

How to eliminate wrong answers

Option A is wrong because creating a new KMS key each year and updating the Redshift cluster requires manual re-encryption of all data and reconfiguration of the cluster, causing significant operational impact and potential downtime. Option B is wrong because AWS Lambda is unnecessary and adds complexity; KMS already provides built-in automatic rotation that does not require custom code or scheduling. Option D is wrong because re-importing key material into an existing KMS key is only applicable to imported key material (not AWS-generated keys) and does not meet the requirement for annual rotation of an AWS KMS key; it also requires manual steps and does not automate the rotation schedule.

94
Multi-Selectmedium

A company wants to protect sensitive data stored in Amazon S3. Which TWO actions should the company take to meet this goal? (Choose TWO.)

Select 2 answers
A.Enable S3 Transfer Acceleration.
B.Configure S3 event notifications to send events to Amazon SNS.
C.Enable S3 Block Public Access.
D.Enable S3 Object Lock.
E.Enable default encryption on the bucket.
AnswersC, E

Enabling S3 Block Public Access adds a strong, explicit layer of protection that can block public reading or writing through bucket policies, ACLs, or object ACLs, even if those public grants are unintentionally set. This control operates at both bucket and account levels and is a primary safeguard against data exposure caused by misconfigurations, making it essential for sensitive data.

Why this answer

Option C (Enable S3 Block Public Access) is correct because it applies account- and bucket-level settings that reject any ACL or bucket policy granting public access, preventing accidental exposure of sensitive objects to the internet. Option E (Enable default encryption on the bucket) is correct because it ensures every object is encrypted at rest with SSE-S3 or SSE-KMS automatically, protecting data confidentiality even if storage media is compromised. Option A (S3 Transfer Acceleration) only speeds up uploads/downloads via edge locations and does not protect data.

Option B (S3 event notifications to Amazon SNS) merely reports object events and provides no security control. Option D (S3 Object Lock) enforces WORM retention to prevent deletion or modification, which addresses integrity/retention rather than protecting sensitive data from unauthorized access or disclosure.

Exam trap

SCS-C02 often tests whether candidates confuse availability/performance features (Transfer Acceleration) or event-driven features (SNS notifications) with actual data protection controls, and whether they recognize that Object Lock addresses integrity/retention rather than confidentiality.

95
MCQhard

A company wants to share an encrypted Amazon Machine Image (AMI) with another AWS account. The AMI uses an EBS snapshot encrypted with a customer managed key in KMS. What is the correct procedure to allow the other account to launch an EC2 instance from this AMI?

A.Export the snapshot as an unencrypted snapshot and share it.
B.Share the AMI and have the target account create a new KMS key to encrypt the snapshot.
C.Share only the AMI; the snapshot permissions are inherited from the AMI.
D.Share the AMI, share the snapshot, and grant the target account decrypt permissions on the KMS key.
AnswerD

This is correct because launching a cross-account encrypted AMI requires three separate sharing actions: the AMI itself via ModifyImageAttribute, each backing snapshot via ModifySnapshotAttribute, and the KMS key via a key policy update that grants the target account decrypt permissions. The target account's IAM roles or users must be able to call kms:Decrypt (and kms:CreateGrant for the launch to create a grant) on the source CMK. After these steps, the target can launch the instance and optionally re-encrypt the resulting volumes with its own KMS key. This layered authorization is the standard, supported pattern for sharing encrypted AMIs across accounts.

Why this answer

An encrypted EBS snapshot backed by a customer managed KMS key requires three separate permissions to be shared: the AMI must be shared with the target account, the underlying snapshot must be shared (modify-snapshot-attribute), and the KMS key policy must grant the target account kms:Decrypt and kms:CreateGrant (and typically kms:DescribeKey). Without all three, the target account cannot launch an instance because it cannot decrypt the snapshot volumes.

Exam trap

SCS-C02 often tests the layered nature of encrypted AMI sharing — candidates assume sharing the AMI is sufficient, forgetting that snapshot permissions and KMS key policy grants are separate, mandatory steps.

How to eliminate wrong answers

Option A is wrong because exporting an unencrypted snapshot defeats the purpose of encryption and is also blocked by AWS for snapshots encrypted with a customer managed key unless you first decrypt them — and it violates the security requirement. Option B is wrong because the target account cannot re-encrypt a snapshot it cannot decrypt; creating a new KMS key does not grant access to the source key's ciphertext. Option C is wrong because AMI sharing does not propagate snapshot permissions — snapshot sharing is a separate API call, and KMS key permissions are a third, independent layer.

96
MCQmedium

A company is designing a data protection solution for Amazon S3 that must prevent any user from accidentally deleting objects. Which combination of S3 features should be used?

A.Use S3 Cross-Region Replication to another bucket.
B.Enable S3 Object Lock with governance mode.
C.Configure S3 default encryption with SSE-KMS.
D.Enable S3 Versioning and MFA Delete.
AnswerD

Enabling S3 Versioning together with MFA Delete is the correct answer because versioning preserves every overwrite and deletion as a previous version, while MFA Delete adds a second-factor requirement for permanently erasing versions or changing the bucket's versioning state. When an object is deleted, S3 simply creates a delete marker and the prior versions remain recoverable; without the MFA token, even the AWS account root user cannot permanently delete a version, which effectively prevents accidental or malicious deletion.

Why this answer

Enabling S3 Versioning preserves all object versions, allowing recovery of deleted objects, and MFA Delete requires multi-factor authentication for permanent deletions, preventing accidental or unauthorized deletions. Option A is wrong because Cross-Region Replication copies objects to another bucket but does not prevent deletion of the source objects. Option B is wrong because Object Lock with governance mode prevents overwrites and deletions only if a retention period is set, but it does not block deletion of the bucket itself or version-level deletions if the lock is not applied.

Option C is wrong because default encryption (SSE-KMS) protects data at rest but does not prevent deletion of objects.

97
MCQmedium

A security engineer is designing a solution to protect data in transit for a web application that uses an Application Load Balancer (ALB) and EC2 instances. The application must use TLS 1.2 or higher and must use a strong cipher suite. The engineer has configured the ALB with a security policy that includes TLS 1.2 and strong ciphers. However, the engineer notices that some clients are still able to connect using TLS 1.0. What is the most likely cause of this issue?

A.The ALB listener is configured with a security policy that includes TLS 1.0, and the engineer's changes were not applied to the correct listener.
B.The EC2 instances behind the ALB are configured to allow TLS 1.0, and the ALB is passing through the TLS connection.
C.The clients are using a proxy that downgrades the TLS version, and the ALB cannot enforce the minimum TLS version.
D.The ALB is configured with a default security policy that allows TLS 1.0.
AnswerA

If the engineer updated the security policy on one listener but the application uses another listener (e.g., a different port), clients connecting to the unchanged listener could still use TLS 1.0. This is a common misconfiguration where changes are applied to the wrong listener or the listener is not updated. The scenario states that some clients can use TLS 1.0, indicating that a listener with a permissive policy is still active.

Why this answer

The most likely cause is that the security policy change was not applied to the correct listener. ALBs can have multiple listeners, and if the application uses a different listener that still has a permissive security policy, clients can connect with TLS 1.0. The engineer should verify all listeners and ensure the restrictive policy is applied to the one handling the traffic.

Exam trap

The trap here is assuming that updating the security policy on one listener automatically applies to all listeners, but each listener must be configured separately.

98
Matchingmedium

Match each AWS security-related acronym to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Center for Internet Security

Payment Card Industry Data Security Standard

Health Insurance Portability and Accountability Act

System and Organization Controls

International standard for information security management

Why these pairings

The correct matches are: SOC with service organization controls, PCI DSS with credit card security, HIPAA with healthcare privacy, and FedRAMP with cloud authorization. Common confusions include mixing HIPAA with SOC and PCI DSS with FedRAMP.

99
MCQmedium

A company uses AWS KMS to encrypt data in Amazon S3. The security team wants to ensure that when an object is retrieved, it is automatically decrypted. They have configured the S3 bucket to use SSE-KMS with a customer managed key. However, when a user downloads an object using the AWS CLI, the object is still encrypted. The IAM policy for the user includes kms:Decrypt permission. What is the MOST likely reason for this issue?

A.The KMS key policy does not allow the user to decrypt.
B.The user is using SSE-C instead of SSE-KMS.
C.The user does not have s3:GetObject permission.
D.The user is not specifying the correct encryption context in the request.
AnswerA

With SSE-KMS, S3 invokes kms:Decrypt using the requesting user's credentials every time an encrypted object is read. The KMS key policy is the resource-based policy that controls which principals can use the key; if it does not grant the user (or the user's role) kms:Decrypt, the KMS call is denied even when the user's IAM policy allows s3:GetObject. That denial manifests as an AccessDenied error during object retrieval.

Why this answer

The most likely reason is that the KMS key policy does not allow the user to decrypt. Even though the user's IAM policy includes kms:Decrypt, KMS requires that both the IAM policy and the key policy grant permission. Since the key policy is separate, it may not include the user as a principal.

Option B is incorrect because SSE-C is not indicated. Option C is incorrect because s3:GetObject is needed but the issue is decryption. Option D is incorrect because encryption context is not required for automatic decryption via S3; S3 manages it transparently.

Exam trap

Candidates often forget that KMS key policies can override IAM permissions. Even with IAM kms:Decrypt, the key policy must explicitly allow the user.

100
MCQeasy

A company is using Amazon S3 to store sensitive data. They want to ensure that all objects uploaded to a specific bucket are encrypted using server-side encryption with AWS KMS. Which bucket policy condition should be used to enforce this?

A.Condition: 's3:x-amz-server-side-encryption-customer-algorithm': 'AES256'
B.Condition: 's3:x-amz-server-side-encryption': 'aws:kms'
C.Condition: 's3:x-amz-server-side-encryption-aws-kms-key-id': 'arn:aws:kms:...'
D.Condition: 's3:x-amz-server-side-encryption': 'AES256'
AnswerB

This is the correct condition because the x-amz-server-side-encryption request header, when set to 'aws:kms', explicitly instructs S3 to encrypt the object with an AWS KMS-managed CMK upon upload. A bucket policy or IAM policy condition that checks this key and value will deny requests that specify a different encryption mode, but note that a robust enforcement policy should also explicitly deny requests that omit the header entirely (using a StringNotEquals condition) to prevent unencrypted uploads.

Why this answer

The bucket policy condition `s3:x-amz-server-side-encryption` with value `aws:kms` enforces that any PutObject request must include the `x-amz-server-side-encryption` header set to `aws:kms`. This ensures that objects are encrypted using SSE-KMS. The condition key is specific to the encryption algorithm, not the KMS key ID.

Exam trap

SCS-C02 often tests the difference between SSE-S3, SSE-KMS, and SSE-C condition keys. Candidates may confuse the condition key for the encryption algorithm with the one for the KMS key ID, or mistakenly use the customer algorithm key for KMS.

How to eliminate wrong answers

Option A is wrong because `s3:x-amz-server-side-encryption-customer-algorithm` is used for SSE-C (customer-provided keys) and expects values like `AES256`, not for KMS. Option C is wrong because `s3:x-amz-server-side-encryption-aws-kms-key-id` checks for a specific KMS key ID, but the requirement is to enforce KMS encryption, not a particular key. Option D is wrong because `AES256` corresponds to SSE-S3 (Amazon S3-managed keys), not SSE-KMS.

101
MCQmedium

A company stores sensitive data in Amazon S3 and requires that objects are automatically encrypted using server-side encryption with AWS KMS. The bucket policy must deny any PUT request that does not include the x-amz-server-side-encryption header with value aws:kms. Which bucket policy condition key should be used?

A.s3:x-amz-server-side-encryption
B.aws:SourceIp
C.aws:RequestedRegion
D.kms:EncryptionContext
AnswerA

The s3:x-amz-server-side-encryption condition key is the correct way to enforce encryption in an S3 bucket policy, as it directly evaluates the x-amz-server-side-encryption header that clients must include in PutObject requests. You can combine it with StringEquals to require a specific value such as aws:kms or AES256, and use a Deny effect to reject any upload lacking the required encryption header. This condition key is evaluated by S3 during the request, making it a precise, application-level control that cannot be bypassed by network or regional context.

Why this answer

The condition key s3:x-amz-server-side-encryption can be used to check the header value. Condition key aws:SourceIp is for source IP; aws:RequestedRegion is for region; kms:EncryptionContext is for KMS encryption context. Option A is correct.

102
MCQhard

A company is implementing a data loss prevention (DLP) solution for data stored in Amazon S3. The data includes personally identifiable information (PII). The company wants to automatically identify and classify PII objects, then apply encryption using AWS KMS with a customer-managed key. Which AWS service should be used to identify PII?

A.AWS CloudTrail
B.Amazon Macie
C.Amazon GuardDuty
D.AWS Config
AnswerB

Amazon Macie is a fully managed data security and privacy service that uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data in Amazon S3, including PII, PHI, and financial information. It supports DLP by generating custom findings and sending alerts via Amazon EventBridge or AWS Security Hub, and it can integrate with AWS Organizations to scale across multiple accounts. Macie provides both managed data identifiers and custom identifiers so customers can detect proprietary or regulatory data types.

Why this answer

Amazon Macie is the correct service because it uses machine learning and pattern matching to automatically discover, classify, and protect sensitive data such as PII in Amazon S3. AWS CloudTrail (Option A) logs API calls and does not inspect data content. Amazon GuardDuty (Option C) detects threats and unauthorized behavior, not data classification.

AWS Config (Option D) evaluates resource configurations and compliance, not data content. Therefore, Option B is correct.

103
MCQmedium

A security engineer runs the command shown in the exhibit. What is the primary purpose of this command?

A.To generate a data key without plaintext.
B.To re-encrypt an existing encrypted file under a new key.
C.To decrypt the file secret.txt using a KMS key.
D.To encrypt the contents of secret.txt using a KMS key and store the result in encrypted_secret.txt.
AnswerD

The command invokes the KMS Encrypt API by taking the plaintext bytes from secret.txt, sending them with the specified key ID, and writing the returned base64-encoded `CiphertextBlob` to encrypted_secret.txt. This is the direct encryption of the file's contents under the given KMS key, producing ciphertext that can later be decrypted only with the same key (and any required encryption context). Because KMS Encrypt accepts plaintext up to only 4 KB, this approach is appropriate for small secrets like passwords or configuration values, not for large files.

Why this answer

The command shown in the exhibit is 'aws kms encrypt --key-id <key-id> --plaintext fileb://secret.txt --output text --query CiphertextBlob | base64 --decode > encrypted_secret.txt'. This command uses the AWS KMS Encrypt API to encrypt the contents of secret.txt with the specified KMS key, then decodes the base64-encoded ciphertext and writes it to encrypted_secret.txt. Therefore, the primary purpose is to encrypt the file contents using a KMS key and store the result in encrypted_secret.txt.

Exam trap

The trap is confusing the KMS Encrypt API with other KMS operations like GenerateDataKey or ReEncrypt. Candidates might think the command is for generating a data key or re-encrypting, but the presence of '--plaintext fileb://' clearly indicates encryption of plaintext data.

How to eliminate wrong answers

Option A is wrong because generating a data key without plaintext is done with 'aws kms generate-data-key-without-plaintext', not the encrypt command. Option B is wrong because re-encrypting an existing encrypted file under a new key would use 'aws kms re-encrypt', which takes a ciphertext blob as input, not a plaintext file. Option C is wrong because decrypting a file would use 'aws kms decrypt' with a ciphertext blob, not encrypt.

104
Multi-Selecthard

A company has a requirement to automatically rotate encryption keys for S3 objects every 90 days. They are using SSE-KMS with a customer managed key. Which action will meet the requirement without breaking access to existing objects?

Select 1 answer
A.Configure an S3 lifecycle policy to re-encrypt objects
B.Use S3 Batch Operations to re-encrypt existing objects with the new key
C.Manually rotate the key every 90 days and re-encrypt all objects
D.Delete the existing key and create a new one each 90 days
E.Enable automatic key rotation in AWS KMS for the customer managed key
AnswersB

Correct. S3 Batch Operations can re-encrypt existing objects with a new key, and the old key remains active for decryption.

Why this answer

(S3 Batch Operations) allows re-encrypting existing objects with a new key without breaking access because the previous key remains available for decryption. Option E (Enable automatic key rotation in AWS KMS) rotates the key annually, not every 90 days, so it does not meet the requirement. No other combination of options fully satisfies the 90-day rotation requirement; thus only B is correct.

105
Multi-Selecteasy

Which TWO of the following are valid options for encrypting data at rest in Amazon S3? (Choose 2.)

Select 2 answers
A.SSL/TLS encryption
B.IAM policy encryption
C.SSE-S3
D.CloudHSM client-side encryption
E.SSE-KMS
AnswersC, E

SSE-S3 (Server-Side Encryption with Amazon S3-Managed Keys) is a built-in S3 feature that uses AES-256 to encrypt each object at rest with a unique data key, and the data key itself is encrypted with a regularly rotated master key managed by S3. You enable it by setting the x-amz-server-side-encryption header to AES256 or by applying a bucket default encryption policy, and S3 fully handles the key lifecycle—requiring no customer key management or extra cost.

Why this answer

SSE-S3 is correct because it provides server-side encryption where Amazon S3 manages the encryption keys entirely. When you upload an object, S3 encrypts it using AES-256 before writing to disk and decrypts it when you access it, with no additional configuration needed beyond enabling the header `x-amz-server-side-encryption: AES256`.

Exam trap

The trap here is confusing encryption at rest with encryption in transit, leading candidates to select SSL/TLS, or misinterpreting IAM policies as an encryption mechanism, or assuming CloudHSM is a native S3 server-side encryption option rather than a client-side tool.

106
Drag & Dropmedium

Drag and drop the steps to configure a VPC with private subnets and NAT gateway for outbound internet access in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

VPC creation, subnets, internet gateway, NAT gateway, and route table update are required for private subnet internet access.

107
MCQmedium

A company is designing a data encryption solution for its Amazon RDS for PostgreSQL database. The database must be encrypted at rest. What is the simplest way to achieve this?

A.Enable encryption when creating the RDS instance using a KMS key.
B.Enable AWS KMS encryption on the RDS instance after creation.
C.Use application-level encryption before inserting data into the database.
D.Use AWS CloudHSM to encrypt the EBS volumes attached to the RDS instance.
AnswerA

Native RDS encryption at rest is a one-way, create-time configuration: you specify a customer-managed AWS KMS key (or the default aws/rds key) when launching the DB instance, and RDS uses envelope encryption to encrypt the instance's storage, automated backups, snapshots, and read replicas. Because the encryption decision is baked into the underlying storage during provisioning, it cannot be retroactively applied to an already-running instance. This is the simplest and most operationally transparent way to meet an at-rest encryption requirement for Amazon RDS.

Why this answer

RDS supports encryption at rest for new databases using AWS KMS. Option B is incorrect because there is no separate encryption layer; RDS uses KMS. Option C is incorrect because application-level encryption is not the simplest.

Option D is incorrect because RDS does not support CloudHSM for encryption at rest.

108
MCQmedium

A company wants to use client-side encryption for data uploaded to Amazon S3. The encryption keys must be managed by the company and never sent to AWS. Which S3 encryption option supports this requirement?

A.Server-side encryption with AWS KMS (SSE-KMS).
B.Client-side encryption using the Amazon S3 encryption client.
C.Server-side encryption with S3 managed keys (SSE-S3).
D.Server-side encryption with customer-provided keys (SSE-C).
AnswerB

The Amazon S3 encryption client performs all cryptographic operations locally, encrypting the object's plaintext with a data key before anything is transmitted; the resulting ciphertext and an encrypted copy of the data key are then uploaded. The plaintext data key is never sent to AWS, and you can choose to wrap the data key with a KMS key or an internal master key that remains entirely under your control. This design is exactly what is needed when only the customer should ever possess the unencrypted form of the data.

Why this answer

Client-side encryption using the Amazon S3 encryption client is correct because the encryption process occurs entirely on the client side before data is uploaded to S3. The company manages the encryption keys locally and never transmits them to AWS, satisfying the requirement that keys are never sent to AWS.

Exam trap

The trap here is that candidates often confuse SSE-C with client-side encryption, not realizing that SSE-C still transmits the encryption key to AWS over the network, albeit encrypted in transit, which violates the 'never sent to AWS' requirement.

How to eliminate wrong answers

Option A is wrong because SSE-KMS uses AWS KMS to manage encryption keys, and the keys are stored and managed by AWS, not the company. Option C is wrong because SSE-S3 uses S3-managed keys that are fully controlled by AWS, not the customer. Option D is wrong because SSE-C requires the customer to provide an encryption key with each request, but the key is sent to AWS over HTTPS for the encryption operation, violating the requirement that keys never be sent to AWS.

109
MCQhard

A company uses AWS CloudHSM to generate and store encryption keys for a custom application. The security team is concerned about key durability and wants to ensure that keys are not lost if the HSM fails. Which action should be taken?

A.Create a multi-region CloudHSM cluster
B.Store the keys in a file on an encrypted EBS volume
C.Use AWS KMS to import the keys from CloudHSM
D.Regularly back up the HSM to an Amazon S3 bucket and restore to a new cluster if needed
AnswerD

CloudHSM automatically stores encrypted backups of each HSM partition in Amazon S3, and you can schedule backups on a regular basis to protect against hardware failure or cluster loss. These backups capture the HSM's key material and data in an encrypted, point-in-time snapshot that can be restored to a new cluster in the same region. By regularly backing up, you ensure that if the cluster becomes unavailable, you can launch a new cluster and restore the backup, preserving access to the keys. This is the supported disaster-recovery mechanism for CloudHSM.

Why this answer

AWS CloudHSM supports taking backups of the HSM content to an Amazon S3 bucket. These backups can be used to restore to a new HSM cluster in case of failure, ensuring key durability. Option A is incorrect because CloudHSM clusters are single-region; multi-region clusters are not supported.

Option B is incorrect because storing keys on an encrypted EBS volume bypasses the security of the HSM and is not a recommended practice for key durability. Option C is incorrect because AWS KMS cannot directly import keys from CloudHSM; KMS and CloudHSM are separate services with different key management capabilities.

Exam trap

Candidates may mistakenly believe that exporting keys to an EBS volume or using KMS provides adequate durability, but CloudHSM's native backup and restore mechanism is the correct method to protect against HSM failure.

110
MCQhard

A company uses Amazon RDS for MySQL with encryption at rest enabled using AWS KMS. They need to ensure that automated backups and snapshots are also encrypted. Which configuration is required?

A.No additional configuration is needed; backups are encrypted automatically.
B.Manually encrypt each snapshot with a separate KMS key.
C.Create a new KMS key and assign it to the backup configuration.
D.Enable encryption on the RDS instance after creation.
AnswerA

Because the RDS MySQL instance already has encryption at rest enabled with a KMS key, all automated backups and manual DB snapshots are encrypted automatically using that same KMS key. AWS handles this at the storage layer with no further input from you, so backup encryption is inherently included.

Why this answer

Amazon RDS automatically encrypts automated backups and snapshots when the source database is encrypted at rest. This encryption is inherited from the primary database, so no additional steps are required. Options B, C, and D are incorrect: manually encrypting each snapshot is unnecessary; assigning a new KMS key to backups is not required; and enabling encryption after creation is not possible for an existing unencrypted instance.

111
MCQeasy

A company needs to securely store database credentials that are used by an application running on Amazon EC2. The credentials must be automatically rotated every 90 days. Which AWS service should be used?

A.AWS KMS
B.AWS Secrets Manager
C.AWS IAM roles for EC2
D.AWS Systems Manager Parameter Store
AnswerB

AWS Secrets Manager is a purpose-built service for storing and managing database credentials, API keys, and other sensitive values. It natively supports automatic rotation of secrets using a customizable AWS Lambda function, with one-click integration for Amazon RDS, Redshift, and DocumentDB to rotate the password on the datastore as well. Because it combines secure storage, fine-grained IAM access control, secret versioning, and scheduled rotation, it directly meets the stated requirement for securely storing database credentials with automatic rotation.

Why this answer

AWS Secrets Manager is purpose-built for storing, retrieving, and automatically rotating database credentials. It natively supports rotation for Amazon RDS, Aurora, and other databases via Lambda rotation functions, and can rotate credentials every 90 days as required. This directly meets the requirement for secure storage and automatic rotation.

Exam trap

SCS-C02 often tests the difference between Secrets Manager and Parameter Store, leading candidates to choose Parameter Store for automatic rotation when it lacks native rotation capabilities.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for encryption keys, not for storing and rotating database credentials. Option C is wrong because IAM roles for EC2 provide temporary credentials for AWS API access, not database credentials, and they do not rotate database passwords. Option D is wrong because Systems Manager Parameter Store can store secrets but does not natively support automatic rotation of database credentials; it requires custom automation.

112
MCQhard

A company uses AWS KMS to encrypt data in Amazon S3. They need to audit all KMS key usage for an S3 bucket. Which AWS service should be used to capture KMS Decrypt API calls?

A.Amazon S3 server access logs
B.Amazon VPC Flow Logs
C.AWS CloudTrail
D.AWS CloudWatch Logs
AnswerC

AWS CloudTrail is the only service listed that natively records the KMS API calls, including the Decrypt operation used when S3 fetches an SSE-KMS-encrypted object. Each KMS event in CloudTrail includes the key ARN, the IAM identity of the caller, the source IP address, and the encryption context, which together provide the complete audit trail required for security investigations. By default, KMS data-plane events like Decrypt are captured in the CloudTrail event history, and you can optionally set up a trail to deliver them to an S3 bucket or CloudWatch Logs for long-term retention.

Why this answer

AWS CloudTrail captures API calls to AWS services, including KMS Decrypt. CloudTrail logs can be delivered to S3 for analysis. Option C is correct.

CloudWatch Logs can receive logs but does not directly capture KMS API calls; S3 server access logs do not include KMS decryption events; VPC Flow Logs capture network traffic, not API calls.

113
MCQmedium

A company is designing a data protection strategy for its Amazon RDS for PostgreSQL database. The database contains sensitive customer data. Compliance requirements mandate that all backups be encrypted at rest and that the encryption keys be rotated annually. Which solution meets these requirements?

A.Create an encrypted read replica of the RDS instance and use the replica for backups.
B.Use S3 server-side encryption with a customer managed key for automated backups. Configure lifecycle policies to rotate the key.
C.Enable encryption at rest on the RDS instance using an AWS managed KMS key. The key will be rotated automatically every year.
D.Enable encryption at rest on the RDS instance using a customer managed KMS key. Enable automatic key rotation in KMS.
AnswerD

Customer managed KMS keys with automatic rotation satisfy both mandates: RDS backups inherit the instance's encryption at rest, and KMS rotates the key annually. AWS managed keys do not offer customer-controlled rotation, so they fail the compliance requirement.

Why this answer

Enabling encryption at rest on the RDS instance with a customer managed KMS key gives the company control over the key, and enabling automatic key rotation in KMS satisfies the annual rotation requirement. Customer managed keys support automatic rotation (default 365 days), unlike AWS managed keys, which cannot be rotated on a customer-defined schedule.

Exam trap

SCS-C02 often tests the difference between AWS managed and customer managed KMS keys, tempting candidates to pick AWS managed keys when the requirement specifies customer-controlled annual rotation.

How to eliminate wrong answers

Option A is wrong because an encrypted read replica does not encrypt the primary instance's automated backups, and using the replica for backups does not address key rotation. Option B is wrong because RDS automated backups are not stored in S3 under customer control — they are managed by RDS and encrypted with the instance's KMS key; S3 SSE with lifecycle policies does not apply. Option C is wrong because AWS managed KMS keys are rotated automatically every three years (not annually) and cannot be configured for annual rotation by the customer.

114
MCQhard

A company uses AWS Secrets Manager to rotate secrets for its RDS database. The rotation fails periodically, and the security team needs to troubleshoot. Which CloudWatch metric should be monitored to detect rotation failures?

A.AWS/KMS: KeyUsage
B.AWS/SecretsManager: SecretRotationSucceeded
C.AWS/Lambda: Invocations
D.AWS/RDS: DatabaseConnections
AnswerB

The AWS/SecretsManager namespace provides SecretRotationSucceeded, which is published after each automatic rotation attempt for a secret and increments when the rotation callback completes successfully. The complementary SecretRotationFailed metric reports failures; by using an alarm on SecretRotationSucceeded with a period and statistic appropriate for the rotation schedule, you can detect missed or unsuccessful rotations. Because this metric is emitted by the Secrets Manager service directly from the rotation process, it is the most precise signal for verifying that rotation is working as configured. For example, you can alarm when SecretRotationSucceeded equals zero for the expected rotation interval.

Why this answer

The correct metric to monitor for Secrets Manager rotation failures is `AWS/SecretsManager:SecretRotationSucceeded`. When rotation fails, the `SecretRotationSucceeded` metric reports a value of 0, allowing the security team to set alarms. Option A is incorrect because KMS key usage metrics are not specific to rotation.

Option C is incorrect because Lambda invocations may not capture all rotation failures and are not a direct indicator. Option D is incorrect because RDS metrics do not include Secrets Manager rotation status.

115
MCQhard

A security engineer is designing a solution to protect sensitive data in an Amazon RDS for MySQL database. The data must be encrypted at rest using a key stored in AWS KMS. Additionally, the database must support automated backups and cross-region disaster recovery. Which architecture meets these requirements?

A.Launch an unencrypted RDS instance, then use AWS DMS to replicate data to an encrypted instance in another region.
B.Launch an unencrypted RDS instance, then enable encryption using the AWS Console after creation.
C.Launch an encrypted RDS instance using the default KMS key, then export the database to S3 and copy to another region.
D.Launch an encrypted RDS instance using a customer-managed KMS key. Enable automated backups and create a cross-region read replica.
AnswerD

Launching an encrypted RDS instance with a customer-managed KMS key ensures data at rest is protected by an encryption key you create and control. Enabling automated backups provides point-in-time recovery, while a cross-region read replica serves as a disaster recovery target that can be promoted to a primary database in a regional outage. This combination fully meets the requirements for encryption, availability, and automated recovery.

Why this answer

Launching an encrypted RDS instance with a customer-managed KMS key satisfies the encryption-at-rest requirement with control over key rotation and access. Enabling automated backups ensures point-in-time recovery, and creating a cross-region read replica provides cross-region disaster recovery — all requirements are met in a single architecture.

Exam trap

SCS-C02 often tests the misconception that encryption can be enabled on an existing RDS instance — candidates forget that encryption must be set at creation and can only be applied to a new instance via snapshot restore.

How to eliminate wrong answers

Option A is wrong because it starts with an unencrypted instance, which violates the encryption-at-rest requirement from the outset, and DMS replication adds complexity without addressing encryption of the source. Option B is wrong because RDS does not allow enabling encryption on an existing unencrypted instance after creation — you must restore from a snapshot into a new encrypted instance. Option C is wrong because exporting to S3 and copying to another region is not a supported cross-region DR mechanism for RDS and does not provide automated failover or replication.

116
Multi-Selectmedium

A security engineer is configuring AWS KMS key policies for a customer managed key used to encrypt data in multiple AWS services. The engineer needs to allow the key to be used by principals in the same account and by a specific IAM role in another account for cross-account access. Which two statements should be included in the key policy to meet these requirements? (Choose two.)

Select 2 answers
A.A statement that allows AWS services to use the key on behalf of the account, with a condition that the request comes from the same account.
B.A statement that allows the account root user to have full KMS permissions, enabling IAM policies in the account to delegate access to the key.
C.A statement that allows all principals in the other account to use the key, with a condition that they have the appropriate IAM permissions.
D.A statement that denies all access to the key except for the account root user, to enforce strict control.
E.A statement that allows the specific IAM role in the other account to use the key for cryptographic operations.
AnswersB, E

Including a statement that allows the account root user full KMS permissions is the standard way to enable IAM policies in that account to control access to the key. Without this, IAM policies alone cannot grant access. This statement effectively delegates control to IAM for principals in the same account, which is necessary for same-account access.

Why this answer

For same-account access, the key policy must allow the account root user full KMS permissions so that IAM policies can delegate access. For cross-account access, the key policy must explicitly allow the external IAM role to use the key. The external role also needs an IAM policy allowing the KMS actions.

These two statements together satisfy the requirements.

Exam trap

The trap here is forgetting that cross-account KMS access requires the key policy to explicitly allow the external principal; an IAM policy in the other account alone is insufficient.

117
Multi-Selecteasy

A company is designing a data protection strategy for Amazon S3. Which TWO of the following are valid methods to protect data at rest in S3?

Select 2 answers
A.S3 Versioning
B.S3 bucket policies
C.MFA Delete
D.Server-side encryption with S3-managed keys (SSE-S3)
E.Server-side encryption with AWS KMS (SSE-KMS)
AnswersD, E

SSE-S3 (Server-Side Encryption with S3-Managed Keys) encrypts objects at rest using S3's native AES-256 encryption, where Amazon S3 fully manages the encryption keys on the customer's behalf. When enabled, S3 automatically encrypts all new objects before persisting them and decrypts them on retrieval, with no additional configuration, key management cost, or KMS API usage. It is the simplest and most lightweight way to meet an encryption-at-rest compliance requirement for S3 data.

Why this answer

Options D and E are correct because both are encryption mechanisms that protect S3 object data at rest: SSE-S3 (D) encrypts objects with AES-256 keys fully managed by Amazon S3, while SSE-KMS (E) encrypts objects using keys managed in AWS KMS, giving you control over key policies, rotation, and audit trails via CloudTrail. These directly satisfy the requirement of protecting data at rest in S3. Option A (S3 Versioning) preserves multiple object versions to aid recovery from overwrites or deletions but does not encrypt data.

Option B (S3 bucket policies) is an access-control mechanism governing who can perform actions on the bucket, not encryption at rest. Option C (MFA Delete) adds an authentication requirement for deleting versions or changing versioning state, which is a deletion-protection control rather than data-at-rest encryption.

Exam trap

The trap here is that candidates often confuse data protection features like versioning or access controls (bucket policies, MFA Delete) with encryption mechanisms, assuming they provide data-at-rest protection when they do not.

118
MCQeasy

A company stores data in Amazon S3 and wants to ensure that objects are encrypted at rest. The security team decides to use server-side encryption with AWS KMS (SSE-KMS). Which additional benefit does SSE-KMS provide over SSE-S3?

A.Faster encryption and decryption
B.Lower cost per object
C.Separate permissions for key usage and audit of key usage
D.Stronger encryption algorithm
AnswerC

SSE-KMS integrates with AWS KMS to provide granular IAM and key policies that separate permissions for who can use a key (e.g., kms:Encrypt, kms:Decrypt) from who can administer it (e.g., kms:PutKeyPolicy, kms:ScheduleKeyDeletion). Additionally, every KMS API call is recorded in AWS CloudTrail, enabling robust audit trails of encryption key usage—something SSE-S3 cannot offer because S3 manages the keys entirely behind the scenes. This separation of duties and auditability is essential for many compliance frameworks, making it the correct benefit.

Why this answer

SSE-KMS provides separate permissions for key usage and allows auditing of key usage via AWS CloudTrail. Option A is incorrect because both SSE-S3 and SSE-KMS use the same AES-256 encryption algorithm for encryption and decryption. Option B is incorrect because SSE-KMS incurs additional costs for KMS API calls, making it more expensive per object than SSE-S3.

Option D is incorrect because both options use the same strong encryption algorithm (AES-256).

119
MCQhard

A company uses AWS CloudTrail to log API activity. The security team wants to ensure that log files are encrypted at rest and that any tampering with logs is detectable. Which combination of services should be used?

A.Enable CloudTrail and configure S3 bucket to use default encryption and enable S3 server access logs.
B.Enable CloudTrail log file SSE-KMS encryption and enable CloudTrail log file integrity validation.
C.Use AWS CloudHSM to generate keys and encrypt CloudTrail logs at the application layer.
D.Enable CloudTrail log file encryption using SSE-S3 and store logs in CloudWatch Logs.
AnswerB

SSE-KMS encrypts CloudTrail log files with a customer-managed KMS key, giving you explicit control over decryption permissions and key rotation. CloudTrail log file integrity validation then publishes signed digest files containing SHA-256 hashes of each log file, allowing you to cryptographically verify that files were not altered or deleted after delivery. The two features together satisfy confidentiality and tamper detection.

Why this answer

CloudTrail log file integrity validation produces digest files signed with SHA-256 and RSA that let you prove logs were not altered or deleted after delivery, while SSE-KMS encryption protects the log objects at rest with a customer-managed or AWS-managed KMS key. Together they satisfy both the confidentiality and tamper-detection requirements. This is the AWS-documented combination for secure, verifiable CloudTrail log storage.

Exam trap

SCS-C02 often tests the difference between encryption at rest and tamper detection — candidates pick SSE-S3 or access logs thinking they cover integrity, when only CloudTrail's digest-based validation actually proves logs were not modified.

How to eliminate wrong answers

Option A is wrong because S3 default encryption (SSE-S3) does not give you control over the key or audit trail of key usage, and S3 server access logs record bucket access, not tampering with log file contents — they do not provide integrity validation. Option C is wrong because CloudHSM is for dedicated HSM key storage and application-layer encryption; CloudTrail does not support encrypting its logs via CloudHSM at the application layer, and this adds complexity without meeting the integrity requirement. Option D is wrong because SSE-S3 lacks KMS key control and CloudWatch Logs is a separate delivery target that does not provide CloudTrail's digest-based integrity validation.

120
MCQeasy

A company needs to encrypt data at rest in Amazon EBS volumes. They want to use an AWS managed key that is automatically rotated. Which encryption option should they choose?

A.Use SSE-S3.
B.Enable EBS encryption by default using the AWS managed key for Amazon EBS.
C.Use a customer-managed KMS key with automatic rotation enabled.
D.Use client-side encryption.
AnswerB

Enable EBS encryption by default establishes that every newly created EBS volume and snapshot is encrypted with the volume's key—the AWS managed key with alias aws/ebs—without requiring per-volume configuration. Because this is an AWS managed key, AWS rotates it automatically and handles the key material, so the company does not need to manage lifecycle or permissions. This satisfies the requirement to encrypt data at rest in the EBS volume directly at the block-storage layer.

Why this answer

Enabling EBS encryption by default using the AWS managed key for Amazon EBS (alias `aws/ebs`) ensures data at rest is encrypted with a key that is automatically rotated on an annual basis, as required. This key is managed by AWS and requires no manual intervention for rotation, meeting the company's need for a managed, automatically rotated key.

Exam trap

The trap here is that candidates often confuse 'AWS managed key' with 'customer-managed KMS key with automatic rotation enabled,' but the key distinction is that a customer-managed key is not an AWS managed key—it is managed by the customer, even if rotation is automated.

How to eliminate wrong answers

Option A is wrong because SSE-S3 is an encryption option for Amazon S3, not for Amazon EBS volumes; it uses S3-managed keys and is irrelevant to EBS encryption. Option C is wrong because while a customer-managed KMS key can have automatic rotation enabled, it is not an AWS managed key—it is customer-managed, meaning the customer retains control and responsibility, which does not satisfy the requirement for an AWS managed key. Option D is wrong because client-side encryption occurs before data reaches AWS and does not use an AWS managed key; it requires the customer to manage encryption keys locally, contradicting the need for an AWS managed, automatically rotated key.

121
MCQhard

Refer to the exhibit. A security engineer is reviewing the CloudWatch Logs configuration for a Lambda function. The log group is encrypted with a customer managed key. The engineer needs to ensure that only the Lambda service can write logs to this log group and that only a specific IAM role can read logs. Which additional configuration is required?

A.Attach a resource-based policy to the log group that allows only the Lambda service to write logs
B.Create an S3 bucket policy to allow only Lambda to write to the log group
C.Assign an IAM role to the log group that has permission to write logs
D.Add a condition to the KMS key policy that uses kms:ViaService to restrict encryption/decryption to logs.amazonaws.com and a condition that the Lambda function is the source
AnswerD

This is correct because the KMS key policy is the authoritative control for who can use the customer-managed key, and CloudWatch Logs calls KMS on behalf of the Lambda function when encrypting/decrypting log data. Adding a statement with Principal as logs.amazonaws.com and a condition using kms:ViaService logs.<region>.amazonaws.com restricts the key's use to calls that come through the CloudWatch Logs service endpoint. To ensure the request is tied to the specific Lambda function, you would also include a condition such as aws:SourceArn matching the Lambda function ARN or an EncryptionContext condition on the log group ARN, so the key cannot be used for unrelated log groups or services.

Why this answer

To ensure only the Lambda service can write logs and only a specific IAM role can read logs, you need to use KMS key policy conditions. The key policy should include a condition that allows CloudWatch Logs to use the key for encryption/decryption only when the request originates from the Lambda service (using kms:ViaService condition). Additionally, you can restrict read access by specifying the IAM role in the key policy.

Option A is incorrect because resource-based policies on log groups cannot restrict write access to Lambda only; they are typically used for cross-account access. Option B is incorrect because S3 bucket policies are not applicable to CloudWatch Logs. Option C is incorrect because you cannot assign an IAM role to a log group; IAM roles are assumed by entities, not assigned to resources.

122
MCQeasy

The above CLI output shows the encryption configuration for an S3 bucket. What type of encryption is enabled by default?

A.SSE-C
B.Client-side encryption
C.SSE-KMS
D.SSE-S3
AnswerD

The CLI output shows SSEAlgorithm set to 'AES256', which is the exact algorithm identifier that Amazon S3 uses to represent SSE-S3 in a bucket default encryption configuration. With SSE-S3, S3 automatically manages all encryption keys, encrypts each object with a unique key, and wraps that key with a regularly rotated master key, requiring no customer action or KMS involvement. This precisely matches the output shown, confirming that the bucket is configured for SSE-S3.

Why this answer

SSE-S3 (AES-256) is the default encryption applied by Amazon S3 when no explicit encryption configuration is set on a bucket. The CLI output showing 'ApplyServerSideEncryptionByDefault' with 'SSEAlgorithm: AES256' indicates SSE-S3, where S3 manages the keys entirely. SSE-KMS would show 'aws:kms' and a KMS key ARN, while SSE-C requires customer-provided keys per request.

Exam trap

SCS-C02 often tests the confusion between SSE-S3 and SSE-KMS by showing CLI output with 'AES256' and expecting candidates to recognize it as the S3-managed default rather than assuming KMS is always used for sensitive data.

How to eliminate wrong answers

Option A is wrong because SSE-C requires the customer to supply the encryption key with every PUT/GET request via headers; it is never a bucket default and would not appear as an AES256 default algorithm. Option B is wrong because client-side encryption happens before data reaches S3, so S3's encryption configuration would not reflect it. Option C is wrong because SSE-KMS would display 'aws:kms' as the SSEAlgorithm and reference a KMS key ARN, not plain AES256.

123
Multi-Selecteasy

A company wants to protect data stored in Amazon S3 Glacier. The data must be encrypted at rest and the encryption keys must be rotated annually. Which TWO options meet these requirements?

Select 2 answers
A.Use SSE-KMS with a customer-managed key that has automatic key rotation enabled.
B.Use AWS CloudHSM to generate a key and encrypt data before uploading to Glacier.
C.Use client-side encryption with the Amazon S3 encryption client.
D.Use SSE-C with keys stored in AWS Secrets Manager and rotate keys annually.
E.Use the default encryption provided by S3 Glacier (SSE-S3).
AnswersA, E

SSE-KMS with a customer-managed AWS KMS key that has automatic rotation enabled satisfies the requirement because S3 Glacier applies server-side encryption using KMS, and KMS automatically rotates the underlying key material on an annual basis without any manual action. The CMK remains the same logical key, so object references and permissions are unchanged while the encryption material is refreshed, meeting compliance policies that demand automatic key rotation. This is the most flexible option when you need separate permissions and audit trails.

Why this answer

SSE-KMS with a customer-managed key that has automatic key rotation enabled allows annual rotation and meets the encryption requirement. Option E is correct because S3 Glacier's default encryption, SSE-S3, encrypts data at rest and AWS manages key rotation automatically on an annual basis. Option B is incorrect because AWS CloudHSM requires manual key rotation.

Option C is incorrect because client-side encryption with the Amazon S3 encryption client does not use server-side encryption and requires manual key management. Option D is incorrect because SSE-C requires you to manage and rotate the keys manually.

124
Multi-Selectmedium

A security engineer is designing a data protection strategy for an S3 bucket that contains sensitive documents. The bucket is accessed by multiple IAM users and roles. Which TWO actions will help protect the data at rest and in transit?

Select 2 answers
A.Enable S3 Access Logs and send them to a separate account
B.Add a bucket policy that denies requests without aws:SecureTransport
C.Enable MFA Delete on the S3 bucket
D.Enable default encryption on the S3 bucket using SSE-S3 or SSE-KMS
E.Use pre-signed URLs for all access
AnswersB, D

Denying requests lacking `aws:SecureTransport` enforces TLS on every S3 API call, satisfying the in-transit encryption requirement. The condition evaluates the transport protocol of each request, so any IAM user or role attempting plain HTTP access is rejected regardless of identity permissions. This protects sensitive documents during transmission without altering stored object encryption.

Why this answer

Enforcing HTTPS (aws:SecureTransport) protects data in transit by requiring all requests to use TLS. Option D is correct because enabling default encryption (SSE-S3 or SSE-KMS) ensures data at rest is automatically encrypted when written to S3. Option A is incorrect: S3 Access Logs are for auditing access, not for protecting data.

Option C is incorrect: MFA Delete protects against accidental deletion, not data protection at rest or in transit. Option E is incorrect: pre-signed URLs provide time-limited access but do not inherently protect data at rest or enforce encryption in transit.

Exam trap

Candidates often confuse auditing (Access Logs) or deletion protection (MFA Delete) with data protection mechanisms. The question specifically asks for protecting data at rest and in transit, which are encryption and transport enforcement.

125
MCQhard

A company uses AWS KMS to encrypt secrets stored in AWS Secrets Manager. The security team wants to audit all KMS key usage, including attempts to use the key without proper authorization. Which AWS service should the team use to meet this requirement?

A.Amazon GuardDuty
B.AWS Config
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail is the only service here that natively captures every KMS API operation as an audit event, including both management-plane calls like CreateKey and PutKeyPolicy and data-plane cryptographic calls such as Encrypt, Decrypt, and GenerateDataKey when data events are enabled. Each log entry contains the requesting IAM principal, source IP, request parameters, and response elements, and even records access-denied events from failed authorization attempts, giving security teams a complete, tamper-evident trail for compliance investigations. Because CloudTrail delivers events to an S3 bucket and optionally to CloudWatch Logs, it provides the durable, centralized audit history required by regulators, whereas the other options do not capture KMS API calls directly.

Why this answer

AWS CloudTrail records every API call made to KMS, including successful and failed attempts to use, encrypt, decrypt, or manage keys. Failed attempts due to insufficient permissions are logged as AccessDenied errors, giving the security team the audit trail they need. CloudTrail is the authoritative service for API-level auditing across AWS.

Exam trap

SCS-C02 often tests the distinction between GuardDuty (threat detection) and CloudTrail (audit logging) — candidates pick GuardDuty thinking it audits all API calls, but it only surfaces findings, not raw audit records.

How to eliminate wrong answers

Option A is wrong because GuardDuty is a threat detection service that analyzes logs for malicious activity — it does not provide a complete audit trail of all KMS key usage attempts. Option B is wrong because AWS Config tracks resource configuration changes and compliance, not individual API calls or authorization failures. Option D is wrong because CloudWatch Logs is a log aggregation and monitoring service; while CloudTrail can deliver events to CloudWatch Logs, CloudWatch Logs alone does not capture KMS API activity unless CloudTrail is already feeding it.

126
MCQmedium

A security engineer is designing a solution to encrypt data at rest in an Amazon DynamoDB table. The data must be encrypted with a customer managed key in AWS KMS that the security team can rotate annually. The DynamoDB table is used by an AWS Lambda function. Which approach should the engineer take to meet these requirements?

A.Create a customer managed KMS key, enable automatic key rotation with a one-year rotation period, and specify this key when creating the DynamoDB table.
B.Enable DynamoDB encryption at rest with the default AWS owned key and configure annual rotation of that key.
C.Enable DynamoDB encryption at rest with an AWS managed key and manually rotate the key every year using the AWS CLI.
D.Use AWS CloudHSM to generate a custom encryption key and configure DynamoDB to use that key for encryption at rest.
AnswerA

A customer managed KMS key allows the security team to control rotation. Enabling automatic rotation with a one-year period meets the annual rotation requirement. When creating the DynamoDB table, specifying this key ensures all data is encrypted with it. The Lambda function's IAM role must have permissions to use the key for encrypt and decrypt operations.

Why this answer

Using a customer managed KMS key with automatic rotation set to one year gives the security team control over the key lifecycle. DynamoDB supports specifying a customer managed key at table creation. The Lambda function must have IAM permissions to use the key.

This solution meets both the encryption and rotation requirements.

Exam trap

The trap here is assuming that AWS managed keys or AWS owned keys can be rotated on a custom schedule, when in fact only customer managed keys support configurable automatic rotation.

127
MCQeasy

Refer to the exhibit. A security engineer runs the command shown and gets the output. What does this output indicate about the bucket's encryption configuration?

A.The bucket does not allow unencrypted objects.
B.The bucket has default encryption enabled using SSE-KMS.
C.The bucket requires all objects to be encrypted with SSE-KMS.
D.The bucket has default encryption enabled using SSE-S3.
AnswerD

The API response shows "ApplyServerSideEncryptionByDefault" with "SSEAlgorithm": "AES256", which directly maps to S3-managed keys, i.e., SSE-S3. With SSE-S3 default encryption enabled, any object uploaded without an encryption header is automatically encrypted at rest using S3's AES-256 encryption. This is exactly what the get-bucket-encryption output demonstrates, making this the correct interpretation.

Why this answer

The output shows that default encryption is set to AES256, which corresponds to SSE-S3. This means new objects uploaded to the bucket will be encrypted with SSE-S3 unless a different encryption header is provided. Therefore, option D is correct.

Option A is incorrect because the default encryption setting does not prevent unencrypted objects from being uploaded if the client does not provide encryption headers—it only applies encryption by default. Option B is incorrect because SSE-KMS uses a different key management service, not AES256. Option C is incorrect because default encryption does not require all objects to be encrypted with SSE-KMS; it sets a server-side default, but clients can override with their own encryption settings.

128
MCQeasy

A security engineer needs to ensure that an Amazon RDS for MySQL database is encrypted at rest. Which action should be taken?

A.Use a client-side encryption tool to encrypt data before writing to the database.
B.Use AWS KMS to encrypt individual databases within the instance.
C.Enable encryption on an existing unencrypted DB instance.
D.Create a new DB instance with encryption enabled.
AnswerD

Creating a new DB instance with encryption enabled is the correct approach because RDS encryption at rest is enabled at launch using an AWS KMS customer managed key. Once enabled, Amazon RDS transparently encrypts the underlying storage, automated backups, read replicas, and snapshots without requiring any application changes. After the new encrypted instance is created, migrate data from the existing source—either by restoring from an encrypted snapshot or using native database export/import tools—to complete the transition.

Why this answer

Amazon RDS does not support enabling encryption on an existing unencrypted DB instance. Encryption at rest must be configured at instance creation time by selecting the KMS key. Therefore, the only valid path is to create a new DB instance with encryption enabled and migrate data to it.

Exam trap

The trap here is assuming RDS supports in-place encryption toggling like some other AWS services; candidates often pick 'enable encryption on existing instance' because it sounds operationally convenient, but RDS requires instance recreation.

How to eliminate wrong answers

Option A is wrong because client-side encryption protects data before it reaches RDS but does not satisfy the requirement for RDS encryption at rest, which is a storage-layer feature managed by AWS. Option B is wrong because AWS KMS encrypts the underlying storage volume of the DB instance, not individual databases inside the instance; RDS does not expose per-database encryption controls. Option C is wrong because RDS does not allow enabling encryption on an existing unencrypted DB instance — the instance must be recreated from a snapshot with encryption enabled.

129
MCQeasy

A company wants to protect data at rest for an Amazon RDS for PostgreSQL database. Which AWS service should be used to manage the encryption keys?

A.AWS CloudHSM
B.AWS Key Management Service (KMS)
C.AWS Certificate Manager (ACM)
D.AWS Secrets Manager
AnswerB

AWS Key Management Service (KMS) is the correct service for encrypting Amazon RDS data at rest. When you enable RDS encryption, you select a KMS customer master key (CMK) — either the AWS-managed key (aws/rds) or a customer-managed CMK — which encrypts the underlying storage, automated backups, snapshots, and read replicas. KMS also provides fine-grained access control and AWS CloudTrail auditing for every key use, making it the native integration point for RDS storage encryption.

Why this answer

Amazon RDS for PostgreSQL integrates with AWS Key Management Service (KMS) to enable encryption at rest. When you enable encryption for an RDS DB instance, KMS manages the customer master keys (CMKs) that encrypt the data keys used by the storage layer. This is the standard, fully managed key management service for RDS encryption, supporting automatic key rotation and fine-grained access control.

Exam trap

The trap here is that candidates confuse AWS Secrets Manager (which manages secrets like passwords) with KMS (which manages encryption keys), leading them to select Secrets Manager for key management instead of the correct service for RDS encryption at rest.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides hardware security modules for key generation and storage but does not integrate directly with RDS for encryption at rest; RDS relies on KMS for key management, not CloudHSM. Option C is wrong because AWS Certificate Manager (ACM) handles SSL/TLS certificates for securing data in transit, not encryption keys for data at rest. Option D is wrong because AWS Secrets Manager is designed to rotate and manage database credentials and other secrets, not to manage the encryption keys used for RDS storage encryption.

130
MCQmedium

A company is using AWS KMS to encrypt data in Amazon S3. The security team wants to ensure that only a specific IAM role can decrypt the data. What is the MOST secure way to enforce this?

A.Attach an IAM policy to the role granting kms:Decrypt
B.Configure the KMS key policy with a condition that allows only the role to decrypt
C.Disable the KMS key and re-enable it only when the role needs to decrypt
D.Configure an S3 bucket policy that denies all principals except the role
AnswerB

A KMS key policy is the resource-based policy that ultimately defines which principals are allowed to use the key. By adding a condition such as aws:PrincipalArn to the kms:Decrypt action, you can limit the permission to a specific IAM role ARN, ensuring that no other principal can invoke decrypt even if they have IAM permissions. The key policy, not IAM, is the controlling restriction here. Always include a statement allowing the account root user to administer the key so you don't lock yourself out.

Why this answer

AWS KMS key policies are the primary resource-based access control for a KMS key. To ensure only a specific IAM role can decrypt, the key policy must explicitly allow that role (and no other principals) for kms:Decrypt, optionally with conditions. IAM policies alone cannot grant access to a KMS key unless the key policy also permits it, making the key policy the authoritative enforcement point.

Exam trap

SCS-C02 often tests the misconception that an IAM policy alone can grant KMS decrypt access, when in fact the KMS key policy must also allow the principal — key policy is the gatekeeper.

How to eliminate wrong answers

Option A is wrong because an IAM policy granting kms:Decrypt is necessary but not sufficient — the KMS key policy must also allow the principal, otherwise access is denied. Option C is wrong because disabling and re-enabling a KMS key is operationally disruptive, does not provide fine-grained per-role control, and can break dependent services; it is not an access-control mechanism. Option D is wrong because an S3 bucket policy controls access to S3 objects/API actions, not to KMS cryptographic operations; it cannot directly restrict who can call kms:Decrypt.

131
MCQhard

A company uses Amazon EBS volumes for EC2 instances. Security policy requires that all EBS volumes be encrypted at rest. The company already has a default KMS key for EBS encryption. However, some new volumes are created without encryption. What is the most efficient way to enforce encryption for all new EBS volumes?

A.Use AWS CloudTrail to monitor volume creation and send alerts
B.Create an AWS Config rule to detect unencrypted volumes and trigger a Lambda function to encrypt them
C.Use a custom AMI that enforces encryption
D.Enable EBS encryption by default in the EC2 console or via the API
AnswerD

Enable EBS encryption by default at the account or region level, either through the EC2 console or the API (EnableEbsEncryptionByDefault). This setting automatically encrypts all newly created volumes, snapshots, and volumes created from those snapshots, using either the default AWS-managed key or a custom KMS key you specify. Because it is enforced at creation time, it is a preventive control that eliminates the risk of accidentally leaving new volumes unencrypted, which is exactly what the security requirement demands.

Why this answer

Enabling EBS encryption by default in the EC2 console or via the API (EnableEbsEncryptionByDefault) ensures that every new EBS volume created in the region is automatically encrypted with the specified KMS key, without requiring any per-volume action or custom tooling. This is the most efficient, native enforcement mechanism because it operates at the account/region level and applies to all volume creation paths, including those from AMIs, snapshots, and instance launches.

Exam trap

SCS-C02 often tests whether candidates choose detective/corrective controls (Config + Lambda, CloudTrail alerts) over the native preventive control (EBS encryption by default), which is simpler and more efficient.

How to eliminate wrong answers

Option A is wrong because CloudTrail only records API activity for auditing — it can detect that an unencrypted volume was created but cannot prevent or remediate it, and alerting is reactive rather than preventive. Option B is wrong because an AWS Config rule with a Lambda remediation function is a detective-and-corrective control that adds latency and complexity; it also requires custom code and does not prevent the unencrypted volume from existing temporarily. Option C is wrong because a custom AMI only enforces encryption for volumes created from that specific AMI — it does not cover volumes created by other means (e.g., from snapshots, other AMIs, or direct volume creation), leaving gaps in enforcement.

132
MCQmedium

A company wants to securely share an Amazon S3 object with an external partner. The partner needs to download the object using an HTTP GET request. The object must be accessible for only 24 hours. What is the most secure way to grant access?

A.Create a new IAM user with read access to the object and share the access key and secret key.
B.Make the object publicly readable and share the object URL.
C.Generate a presigned URL for the object with an expiration of 24 hours.
D.Create a new IAM user with read access to the object, then generate a presigned URL for the object.
AnswerC

A presigned URL is generated by using AWS Signature Version 4 to sign a request for a specific S3 object action, such as GetObject, using the caller's credentials. With a 24-hour expiration, the embedded X-Amz-Expires parameter causes S3 to reject the URL after one day, so the recipient never needs the IAM user's actual secret key. The underlying object stays private because access still passes through S3's authorization layer; the URL only carries the cryptographic signature that proves the request was authorized.

Why this answer

A presigned URL grants time-limited, secure access to a specific S3 object without exposing AWS credentials. The partner can download the object via HTTP GET within the 24-hour expiration window. Option A is incorrect because sharing IAM user credentials is insecure and provides broader access than needed.

Option B is incorrect because making the object public exposes it to anyone, violating security. Option D is incorrect because creating an IAM user is unnecessary; the presigned URL alone provides the required access, and adding a user credential undermines security.

133
MCQmedium

A company uses AWS CloudHSM to store encryption keys. The security team wants to ensure that keys stored in CloudHSM are backed up and can be restored in another AWS Region. What is the BEST approach?

A.Enable automatic cross-region replication on the CloudHSM cluster
B.Copy the HSM user credentials and use them in the new region
C.Use AWS Backup to back up the CloudHSM cluster and restore in another region
D.Export the security domain from the source cluster and import it into a new cluster in the target region
AnswerD

The security domain is the encrypted root-of-trust material generated when a CloudHSM cluster is initialized, and it is required to decrypt cluster backups and recover the keys stored in the HSM. By exporting the security domain from the source cluster and importing or supplying it during the initialization of a new cluster in the target region, you give the new cluster the ability to unlock the restored backup and retrieve the original key material. This is the correct disaster-recovery action, and it must be paired with copying and restoring a CloudHSM backup to that region.

Why this answer

AWS CloudHSM allows you to export the security domain from a source cluster, which contains the cryptographic material needed to back up and restore keys. You can then create a new CloudHSM cluster in the target region and import the security domain to restore the keys. Option A is incorrect because CloudHSM does not support automatic cross-region replication.

Option B is incorrect because HSM user credentials alone do not contain the key material; they are used for authentication, not backup. Option C is incorrect because AWS Backup does not integrate with CloudHSM to back up the cluster's keys.

134
Multi-Selecteasy

Which TWO AWS services provide key management for encryption at rest? (Choose 2.)

Select 2 answers
A.AWS Systems Manager Parameter Store
B.AWS CloudHSM
C.AWS Certificate Manager (ACM)
D.AWS Key Management Service (KMS)
E.AWS Secrets Manager
AnswersB, D

CloudHSM is a dedicated hardware security module that provides FIPS 140-2 Level 3 validated, tamper-resistant devices for generating, storing, and using cryptographic keys. Unlike KMS, CloudHSM gives you exclusive, root-level control over your own HSMs and the entire key lifecycle, independent of AWS-operated key infrastructure.

Why this answer

AWS Key Management Service (KMS) is a managed service that makes it easy to create and control customer master keys (CMKs) used for encrypting data at rest across AWS services like S3, EBS, and RDS. AWS CloudHSM provides dedicated hardware security modules (HSMs) that allow you to manage your own encryption keys in a tamper-resistant hardware appliance, meeting FIPS 140-2 Level 3 compliance for key storage and cryptographic operations. Both services directly provide key management for encryption at rest, with KMS offering integrated key rotation and auditing via AWS CloudTrail, while CloudHSM gives you full control over the HSM appliance and keys.

Exam trap

The trap here is that candidates often confuse AWS Secrets Manager or Systems Manager Parameter Store as key management services because they store encrypted secrets, but they are secret storage services that rely on KMS for encryption and do not provide independent key management for encryption at rest.

135
MCQmedium

A company stores sensitive data in an S3 bucket with default encryption (SSE-S3) enabled. A security audit reveals that objects are being accessed by users from unexpected IP addresses. The company wants to enforce that only objects encrypted with a specific KMS key (managed by the security team) can be accessed. Which combination of actions should be taken?

A.Use SSE-C and distribute the customer key to authorized users only.
B.Modify the bucket policy to deny PutObject and GetObject unless the request includes the specific KMS key ID in the 'x-amz-server-side-encryption-aws-kms-key-id' header.
C.Enable S3 Block Public Access and use AWS WAF to filter IP addresses.
D.Apply an S3 Lifecycle policy to transition objects to Glacier after 30 days.
AnswerB

This enforces use of the specific KMS key for all operations.

Why this answer

It uses a bucket policy with the 's3:x-amz-server-side-encryption-aws-kms-key-id' condition key to deny requests that do not include the specific KMS key ID in the 'x-amz-server-side-encryption-aws-kms-key-id' header. This enforces that only objects encrypted with the specified KMS key can be accessed. Option A is incorrect because SSE-C uses customer-provided keys and does not integrate with KMS key IDs; distributing a customer key does not enforce the specific KMS key.

Option C is incorrect because S3 Block Public Access and AWS WAF do not control access based on encryption key. Option D is incorrect because lifecycle policies do not restrict access based on encryption key.

136
MCQeasy

A company is migrating sensitive customer data to Amazon RDS for MySQL. The security team requires that data be encrypted at rest and in transit. The database will be accessed by a web application running on Amazon EC2 instances in the same VPC. The RDS instance is launched with encryption enabled using an AWS managed KMS key. The security team also enables SSL/TLS for connections. Which additional step is necessary to ensure that the web application uses encrypted connections?

A.Enable encryption at rest on the EC2 instance's EBS volumes.
B.Create an SCP to enforce SSL connections to RDS.
C.Configure the web application's database connection string to use SSL/TLS.
D.Grant the EC2 instance's IAM role permission to use the KMS key for decrypting RDS connections.
AnswerC

The web application must explicitly request TLS because RDS defaults to allowing both encrypted and unencrypted connections depending on the client. Adding an SSL/TLS option to the connection string—such as 'sslMode=require' or 'sslmode=verify-full'—forces the client to negotiate an encrypted channel. This is the only option that directly controls the confidentiality of data as it travels from the application to the RDS database.

Why this answer

Enabling SSL/TLS on the RDS instance allows encrypted connections, but the web application must be configured to actually use SSL/TLS when connecting. This is done by modifying the database connection string to require SSL/TLS. Without this step, the application may connect without encryption.

Exam trap

The trap is thinking that enabling SSL/TLS on RDS is sufficient; candidates may overlook that the client application must be configured to use SSL/TLS, and they may confuse encryption at rest (KMS) with encryption in transit (SSL/TLS).

How to eliminate wrong answers

Option A is wrong because EBS encryption on EC2 instances protects data at rest on the EC2 volumes, not data in transit to RDS. Option B is wrong because an SCP can enforce that SSL connections are used, but it does not configure the application to use SSL; it is a preventive control, not a configuration step. Option D is wrong because IAM permissions for KMS are for encrypting/decrypting data at rest, not for establishing SSL/TLS connections; SSL/TLS uses certificates, not KMS keys.

137
MCQhard

A financial company uses AWS KMS to encrypt sensitive data. The security team notices that a KMS key has been deleted, but the encrypted data is still needed for a short period. What is the fastest way to make the data decryptable again?

A.Contact AWS Support to recover the key material
B.Cancel the key deletion within the waiting period
C.Restore the key from a CloudHSM backup
D.Re-encrypt the data with a new KMS key
AnswerB

When a customer-managed KMS key is scheduled for deletion, KMS enforces a mandatory waiting period (7 to 30 days, configurable) during which the key can be restored using the CancelKeyDeletion operation, which returns the key to its previous enabled state. As long as the original key is restored before the deletion completes, any ciphertext encrypted under that key—including data keys wrapped by the key—remains decryptable, so your data is not lost. The waiting period is designed exactly for this recovery scenario; after it expires, deletion is irreversible and no recovery path exists.

Why this answer

When a KMS key is scheduled for deletion, there is a waiting period (7-30 days) during which the deletion can be cancelled, restoring the key and making the data decryptable. Option A is incorrect because AWS Support cannot recover a deleted KMS key. Option C is incorrect because CloudHSM backups are unrelated to KMS key material.

Option D is incorrect because re-encrypting with a new key would require the original key to decrypt first.

138
Multi-Selectmedium

Which TWO of the following are valid methods to protect data in transit between an on-premises data center and AWS? (Choose two.)

Select 2 answers
A.Amazon CloudFront with HTTPS-only viewer protocol policy
B.AWS Site-to-Site VPN
C.VPC Peering
D.S3 Transfer Acceleration
E.AWS Direct Connect with encryption (MACsec)
AnswersB, E

AWS Site-to-Site VPN establishes a secure IPsec tunnel between your on-premises gateway and a virtual private gateway or transit gateway in AWS. Using IKEv2 and AES encryption, it encrypts all IP traffic traversing the public internet, ensuring confidentiality and integrity for data in transit. This is a core service for hybrid cloud connectivity and a valid method for protecting data.

Why this answer

Options B and E are correct. AWS Site-to-Site VPN creates an encrypted tunnel over the internet, protecting data in transit. AWS Direct Connect with MACsec provides encryption over a private physical connection.

Option A is incorrect because CloudFront with HTTPS only encrypts between viewer and edge locations, not necessarily between the origin and edge, and it is not a method to connect on-premises directly to AWS. Option C is incorrect because VPC Peering does not encrypt traffic; it only routes between VPCs. Option D is incorrect because S3 Transfer Acceleration only speeds up transfers using edge locations but does not provide encryption.

139
MCQeasy

A company uses Amazon S3 to store confidential documents. The security team wants to ensure that all objects are encrypted at rest using server-side encryption with AES-256. Which S3 encryption option should be used?

A.SSE-C
B.SSE-KMS
C.SSE-S3
D.Client-side encryption
AnswerC

SSE-S3 (server-side encryption with Amazon S3 managed keys) is the correct option because it uses strong AES-256 encryption with keys that are managed entirely by Amazon S3. Each object is encrypted with a unique data key, and the data key is wrapped by a regular rotating S3-managed key. This gives S3 the responsibility for encrypting confidential documents with no additional cost, no key rotation overhead, and no need for the customer to supply or manage keys.

Why this answer

SSE-S3 applies server-side encryption with AES-256 using keys fully managed by Amazon S3, meeting the requirement for AES-256 encryption at rest without customer key management overhead. It is the default and simplest S3-managed encryption option, automatically encrypting every object with strong AES-256 and requiring no additional configuration or key infrastructure. This directly satisfies the stated requirement.

Exam trap

SCS-C02 often tests the confusion between 'AES-256' as an algorithm and the key-management model, tempting candidates to select SSE-KMS for stronger-sounding control when the requirement only specifies AES-256 at rest.

How to eliminate wrong answers

Option A (SSE-C) is wrong because it requires the customer to supply and manage their own encryption keys with every request, which is unnecessary complexity when the requirement is simply AES-256 at rest. Option B (SSE-KMS) is wrong because although it uses AES-256, it introduces AWS KMS key management, permissions, and potential API throttling, which exceeds the stated requirement. Option D (client-side encryption) is wrong because it encrypts data before upload, placing key management and cryptographic operations on the customer, and is not server-side encryption at all.

140
MCQeasy

A company stores sensitive customer data in an S3 bucket. The security team wants to ensure that all data is encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). Which bucket policy statement should be added to deny uploads that do not use SSE-KMS?

A.{"Effect":"Deny","Principal":"*","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket-name/*"}
B.{"Effect":"Deny","Principal":"*","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket-name/*","Condition":{"StringNotEquals":{"s3:x-amz-server-side-encryption":"aws:kms"}}}
C.{"Effect":"Deny","Principal":"*","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket-name/*","Condition":{"StringNotEquals":{"s3:x-amz-server-side-encryption":"AES256"}}}
D.{"Effect":"Deny","Principal":"*","Action":"s3:PutObject","Resource":"arn:aws:s3:::bucket-name/*","Condition":{"StringNotEquals":{"s3:x-amz-server-side-encryption":"aws:kms"},"Null":{"s3:x-amz-server-side-encryption-aws-kms-key-id":"true"}}}
AnswerB

This is the correct policy because it uses `StringNotEquals` on the `s3:x-amz-server-side-encryption` header to deny any upload that does not specify `aws:kms`. Requests that omit the encryption header or use `AES256` (SSE-S3) will have a condition that evaluates to true, triggering the Deny, while requests that explicitly send `aws:kms` are permitted. This narrowly enforces SSE-KMS for all new objects without blocking compliant uploads.

Why this answer

The correct bucket policy statement uses a Deny effect on s3:PutObject with a condition that checks if the s3:x-amz-server-side-encryption header is not equal to 'aws:kms'. This ensures that any upload request that does not specify SSE-KMS with AWS KMS is denied. The condition StringNotEquals on that key enforces the requirement.

Exam trap

The trap is confusing the encryption header values: 'aws:kms' for SSE-KMS and 'AES256' for SSE-S3. Candidates might choose the condition that checks for AES256, thinking it enforces KMS, but that would actually enforce SSE-S3. Also, adding extra conditions like Null on key ID can overcomplicate and may not be required.

How to eliminate wrong answers

Option A is wrong because it denies all s3:PutObject requests unconditionally, which would block all uploads, not just those without SSE-KMS. Option C is wrong because it denies uploads that do not use AES256 (SSE-S3), which is the opposite of what is needed; it would allow SSE-KMS but block SSE-S3, but the requirement is to deny non-SSE-KMS, so this condition would actually deny SSE-S3 and allow SSE-KMS, but it's not the correct condition because it checks for AES256, not aws:kms. Option D is wrong because it adds an additional Null condition on the KMS key ID, which would deny uploads that do not specify a KMS key ID, but the requirement is only to enforce SSE-KMS, not necessarily a specific key ID.

This condition would also deny uploads that use SSE-KMS with the default key, which may be too restrictive.

141
Multi-Selectmedium

Which TWO of the following are best practices for protecting data in transit? (Choose TWO.)

Select 2 answers
A.Use a VPN for all traffic
B.Use HTTP for internal traffic
C.Enforce HTTPS for web traffic
D.Use SSL/TLS for all data transfers
E.Use encryption at rest
AnswersC, D

Enforcing HTTPS for web traffic is a critical best practice because HTTPS runs HTTP over TLS, providing confidentiality, integrity, and server authentication for every request and response. Redirecting all HTTP requests to HTTPS and applying HTTP Strict Transport Security (HSTS) ensures clients never send or accept plaintext web communication, mitigating man-in-the-middle and session-hijacking attacks. This should be the baseline for every public-facing web workload and ideally applied to internal web consoles and APIs as well.

Why this answer

Option C is correct because enforcing HTTPS for web traffic ensures that HTTP is wrapped in TLS, providing confidentiality and integrity for browser-to-server communications and preventing eavesdropping or man-in-the-middle tampering on the wire. Option D is correct because using SSL/TLS for all data transfers applies strong, standardized transport encryption (e.g., TLS 1.2/1.3) to any protocol carrying sensitive data, which is the core best practice for protecting data in transit. Option A is not the best answer because a VPN encrypts traffic over an untrusted network but does not by itself secure application-layer transfers end-to-end, and 'all traffic' is overly broad rather than a targeted transit-protection control.

Option B is wrong because plain HTTP transmits data unencrypted and is unsuitable even for internal traffic. Option E is wrong because encryption at rest protects stored data, not data moving across a network.

Exam trap

SCS-C02 often tests the confusion between 'in transit' and 'at rest' controls — candidates pick encryption-at-rest options (KMS, BitLocker) for transit questions, or assume a VPN alone satisfies all transit encryption requirements.

142
MCQeasy

A company needs to encrypt data in transit between an on-premises data center and Amazon S3. Which solution should they use?

A.Use AWS KMS to encrypt the data before transmission.
B.Use an S3 VPC endpoint.
C.Use HTTPS endpoints for S3 API calls.
D.Use S3 Transfer Acceleration.
AnswerC

HTTPS endpoints for S3 API calls use Transport Layer Security (TLS) to encrypt the entire HTTP request and response payload between the on-premises client and the S3 service. This protects the confidentiality and integrity of data in transit, preventing eavesdropping and tampering. Using HTTPS is the standard, built-in mechanism for securing S3 API traffic, and it applies regardless of whether the client is in your VPC or on-premises.

Why this answer

HTTPS (HTTP over TLS) encrypts data in transit between the on-premises data center and Amazon S3 by using TLS 1.2/1.3 to secure the API calls. This ensures that all data transmitted over the network is encrypted end-to-end, protecting it from eavesdropping and man-in-the-middle attacks. AWS S3 enforces HTTPS for all API requests when using the default endpoint, and customers can also configure bucket policies to deny HTTP requests.

Exam trap

The trap here is that candidates often confuse encryption at rest (KMS) with encryption in transit, or assume that network-level features like VPC endpoints or Transfer Acceleration inherently provide encryption, when in fact they do not add transport-layer security beyond what HTTPS already provides.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for encrypting data at rest, not for encrypting data in transit; it does not provide transport-layer encryption during transmission. Option B is wrong because an S3 VPC endpoint (Gateway or Interface type) provides private connectivity to S3 over the AWS network but does not inherently encrypt data in transit; encryption must still be applied at the application layer (e.g., HTTPS). Option D is wrong because S3 Transfer Acceleration optimizes transfer speed by using AWS edge locations and the AWS global network, but it does not add encryption; it relies on the same HTTPS/TLS encryption used by standard S3 endpoints.

143
MCQhard

Refer to the exhibit. A security engineer configures the above KMS key policy. The DataAccess role is used by an application that runs on EC2 instances in the us-east-1 region. The application needs to read encrypted objects from an S3 bucket in the same region. Which of the following is true about this configuration?

A.The role can use the key for any S3 operation in any region.
B.The role cannot use the key for any operation because the condition is invalid.
C.The role can only encrypt data, not decrypt it.
D.The role can decrypt objects in S3, but cannot use the key outside of S3.
AnswerD

The role can decrypt objects in S3 because the policy grants kms:Decrypt and includes a condition that limits the key's use to the S3 service in us-east-1 (for example, kms:ViaService with s3.us-east-1.amazonaws.com). This allows S3 to use the key to decrypt SSE-KMS-encrypted objects. However, the same condition prevents any other service (such as EC2, Lambda, or EBS) from using the key, even within us-east-1. The role also cannot use the key with S3 in other regions, so the overall scope is exactly S3 in us-east-1 for the allowed actions.

Why this answer

The key policy includes a condition 'kms:ViaService' that restricts use of the key to requests that originate from S3 in us-east-1. The DataAccess role has permissions to call kms:Decrypt and kms:GenerateDataKey. With kms:Decrypt, the role can decrypt objects in S3 (e.g., via S3 GetObject with SSE-KMS).

The role can also encrypt objects via S3 PutObject using kms:GenerateDataKey. However, the 'kms:ViaService' condition prevents the role from using the key for any operation outside of S3 (e.g., direct KMS API calls). Option A is incorrect because the condition restricts usage to S3 in us-east-1 only, not any region or any operation.

Option B is incorrect because the condition 'kms:ViaService' is syntactically valid and functions as intended. Option C is incorrect because the role has kms:GenerateDataKey, which allows encryption via S3 PutObject, and kms:Decrypt for decryption, so it can both encrypt and decrypt.

144
MCQmedium

A security engineer is tasked with ensuring that all data stored in an RDS DB instance is encrypted at rest. The database is already running and contains data. What should the engineer do?

A.Change the KMS key associated with the DB instance
B.Modify the DB instance to use an encrypted storage type
C.Create a snapshot of the DB instance, copy it with encryption, and restore the encrypted snapshot
D.Enable encryption at rest in the RDS console for the existing DB instance
AnswerC

To enable encryption-at-rest on an existing unencrypted Amazon RDS DB instance, you must create a manual snapshot, make an encrypted copy of that snapshot (either with the default AWS-managed key or a customer-managed KMS key), and then restore a new DB instance from the encrypted snapshot. During the snapshot copy you can also specify a KMS key; the restored instance will be encrypted, and you can then update your applications' connection strings to point to the new endpoint. This is the documented and only supported approach, since encryption cannot be added in place.

Why this answer

RDS encryption at rest can only be enabled at DB instance creation time; it cannot be turned on for an existing unencrypted instance. The supported migration path is to take a snapshot of the unencrypted instance, copy that snapshot with the encryption option enabled (specifying a KMS key), and then restore a new DB instance from the encrypted snapshot. This produces an encrypted instance containing the same data.

Exam trap

SCS-C02 often tests the immutability of RDS encryption — candidates who assume encryption can be toggled on an existing instance pick the wrong 'modify' option.

How to eliminate wrong answers

Option A is wrong because you cannot change the KMS key on an unencrypted DB instance — there is no key associated with it, and the modify action does not add encryption. Option B is wrong because RDS does not expose an 'encrypted storage type' toggle in the modify-instance API; storage encryption is immutable after creation. Option D is wrong because the RDS console does not offer an 'enable encryption' checkbox for an existing unencrypted instance — that option only appears during creation.

145
MCQmedium

A company needs to encrypt data at rest in Amazon Redshift. They want to use an AWS KMS customer managed key. What is the correct procedure to enable encryption for an existing Redshift cluster?

A.Enable encryption using the Redshift console by selecting the KMS key.
B.Use the AWS CLI command 'aws redshift modify-cluster' with --encrypted flag.
C.Modify the cluster and enable encryption with the KMS key.
D.Take a snapshot of the cluster, restore it to a new cluster with encryption enabled, and point applications to the new cluster.
AnswerD

To add encryption to an existing Redshift cluster, take a snapshot of the source cluster and restore it as a new cluster while specifying a KMS key in the restore settings. The restore operation initializes a fresh cluster with encryption enabled at the storage layer, then you can update your application's JDBC/ODBC connection strings and DNS to point to the new endpoint. Once verified, you can retire the old cluster. This is the only AWS-supported path for retrofitting encryption.

Why this answer

Amazon Redshift does not support enabling encryption on an existing cluster directly. The only way to transition an unencrypted cluster to an encrypted one is to take a snapshot of the cluster, restore it to a new cluster with encryption enabled using a KMS customer managed key, and then redirect applications to the new cluster. This is because encryption settings are immutable after cluster creation.

Exam trap

The trap here is that candidates assume encryption can be toggled on an existing cluster via console or CLI commands, similar to services like RDS or EBS, but Redshift enforces encryption as a cluster-level immutable property.

How to eliminate wrong answers

Option A is wrong because the Redshift console does not allow enabling encryption on an existing cluster; encryption can only be specified at cluster creation or during a restore from snapshot. Option B is wrong because the 'aws redshift modify-cluster' command does not support the --encrypted flag; encryption cannot be modified on a running cluster. Option C is wrong because modifying the cluster to enable encryption with a KMS key is not a supported operation; encryption settings are immutable after creation.

146
MCQmedium

Refer to the exhibit. An administrator applies this bucket policy to an S3 bucket. Which of the following statements describes the effect of this policy?

A.The policy denies all PutObject requests that do not specify SSE-KMS.
B.The policy allows uploads without encryption but denies uploads with SSE-KMS.
C.The policy allows unencrypted uploads but denies uploads with SSE-KMS.
D.The policy allows uploads with SSE-S3 but denies uploads with SSE-KMS.
AnswerA

The policy's Deny effect on s3:PutObject with a condition checking that the encryption header is absent or not SSE-KMS means any upload lacking SSE-KMS encryption is rejected. Requests specifying SSE-KMS satisfy the condition and are permitted.

Why this answer

The bucket policy contains two Deny statements: the first denies PutObject when the `x-amz-server-side-encryption` header is not `aws:kms`, and the second denies PutObject when the header is absent (null). Together, they ensure that any upload without SSE-KMS is denied, effectively requiring SSE-KMS for all PutObject requests. Options B, C, and D are incorrect because the policy does not allow any unencrypted uploads or uploads with SSE-S3; it only allows uploads with SSE-KMS.

Exam trap

The trap is that candidates might misread the policy and think the first statement alone denies all non-KMS encryption, but the second statement is needed to also deny requests with no encryption header at all.

147
MCQhard

A healthcare company runs a HIPAA-compliant application on AWS. The application uses Amazon S3 to store Protected Health Information (PHI). The company has implemented the following controls: (1) All S3 buckets are configured with default encryption using SSE-S3. (2) Bucket policies restrict access to only authorized IAM roles. (3) S3 access logs are enabled and sent to a centralized logging account. (4) MFA Delete is enabled on all buckets. (5) Object lock is not enabled. Recently, an internal auditor discovered that when an authorized user deletes an object, the object is permanently deleted and cannot be recovered. The company's data retention policy requires that deleted PHI be recoverable for at least 30 days after deletion. A review of the IAM policies shows that users have s3:DeleteObject permission. The auditor also notes that the bucket versioning is not enabled. The security team needs to implement a solution that allows authorized users to delete objects but ensures that deleted objects can be recovered within 30 days. Which of the following is the MOST effective course of action?

A.Enable S3 Object Lock in Governance mode with a retention period of 30 days.
B.Enable S3 Versioning on the buckets and ensure that the IAM policies include s3:DeleteObjectVersion where appropriate.
C.Remove the s3:DeleteObject permission from all IAM policies and use S3 Lifecycle policies to expire objects after 30 days.
D.Change the default encryption from SSE-S3 to SSE-C and use a separate key for each object.
AnswerB

S3 Versioning is the correct data-protection mechanism because a regular DELETE on a versioned object only inserts a null-version delete marker while preserving all prior versions, allowing recovery by deleting that marker. Granting the s3:DeleteObjectVersion permission (only where appropriate) enables administrators to permanently purge specific object versions when retention or compliance demands actual deletion, while ordinary deletions remain reversible. This creates a two-tier deletion model where accidental deletes can be untangled and legitimate permanent deletes are still possible, exactly matching the requirement.

Why this answer

Enabling S3 Versioning is the most effective solution because it preserves all object versions, including deleted objects (which become delete markers). With versioning enabled, authorized users can still use s3:DeleteObject to delete the current version, but the previous versions remain recoverable. Since the requirement is to recover deleted PHI within 30 days, versioning combined with a lifecycle policy to permanently delete old versions after 30 days would meet the retention policy without blocking immediate deletion.

Exam trap

The trap here is that candidates may think S3 Object Lock (Option A) is the only way to prevent deletion, but they overlook that versioning allows deletion with recoverability, which directly satisfies the requirement for authorized users to delete objects while retaining the ability to recover them within 30 days.

How to eliminate wrong answers

Option A is wrong because S3 Object Lock in Governance mode prevents any deletion (including overwrites) until the retention period expires, which conflicts with the requirement that authorized users can delete objects immediately. Option C is wrong because removing s3:DeleteObject permission and relying solely on lifecycle policies would prevent users from deleting objects on demand, violating the requirement that authorized users can delete objects. Option D is wrong because changing encryption to SSE-C has no effect on object deletion or recovery; encryption protects data at rest but does not provide versioning or retention capabilities.

148
MCQeasy

A company stores sensitive documents in an S3 bucket. The security team wants to ensure that any object uploaded to the bucket is automatically encrypted using server-side encryption with AWS KMS. Which S3 bucket feature should be configured?

A.Default encryption
B.Versioning
C.Bucket policy
D.Lifecycle policy
AnswerA

Setting default encryption on the bucket is the correct way to ensure that all objects are encrypted at rest automatically. When enabled, Amazon S3 applies server-side encryption (SSE-S3 by default, or SSE-KMS if configured) to every object uploaded to the bucket, even if the upload request does not include an encryption header. This provides a security baseline for sensitive documents and guarantees that no object is stored in an unencrypted state. Unlike policies or lifecycle rules, default encryption directly acts on the data itself at write time.

Why this answer

S3 default encryption (now called default encryption with SSE-KMS or SSE-S3) automatically encrypts every object at rest when it is uploaded, without requiring the uploader to specify encryption headers. Configuring default encryption with SSE-KMS using a customer-managed KMS key satisfies the requirement for automatic server-side encryption with AWS KMS. This is a bucket-level setting applied at PUT time.

Exam trap

SCS-C02 often tests the confusion between access control (bucket policy) and encryption enforcement (default encryption), and candidates may pick bucket policy thinking it encrypts objects.

How to eliminate wrong answers

Option B is wrong because versioning preserves multiple versions of objects but does not encrypt them. Option C is wrong because a bucket policy controls access permissions, not encryption at rest — it can enforce encryption via a condition like s3:PutObject requiring x-amz-server-side-encryption, but it does not itself perform encryption. Option D is wrong because a lifecycle policy manages object transitions and expiration, not encryption.

149
MCQmedium

A company uses AWS Organizations and wants to enforce that all S3 buckets created in any account within the organization have default encryption enabled. Which policy should be used?

A.Use a bucket policy on each bucket to enforce encryption
B.Use a service control policy (SCP) to deny creation of buckets without default encryption
C.Use an IAM policy to require encryption on all bucket creation actions
D.Use AWS Config rules to automatically enable encryption on new buckets
AnswerB

Service control policies set permission guardrails across every account in AWS Organizations, so an SCP denying s3:CreateBucket without default encryption blocks non-compliant buckets organisation-wide. This satisfies the requirement to enforce encryption centrally in all accounts, which bucket policies cannot do.

Why this answer

(SCP) is correct because a service control policy can be applied to all accounts in an AWS Organization to deny the creation of S3 buckets without default encryption, providing a preventive control. Option A is incorrect because bucket policies are applied per bucket and are not preventive during creation. Option C is incorrect because IAM policies are account-specific and do not cover all accounts in the organization.

Option D is incorrect because AWS Config rules are detective, not preventive; they can trigger remediation but do not prevent creation.

150
MCQmedium

A company is using AWS KMS to encrypt data at rest in Amazon S3. The security team requires that all encryption keys be automatically rotated every year. However, the current KMS key policy does not allow rotation. Which action should the security team take to meet the requirement?

A.Manually rotate the key by creating a new key and updating the S3 bucket policy.
B.Use an AWS managed key instead of a customer managed key.
C.Create a new customer managed key with imported key material and enable automatic rotation.
D.Enable automatic rotation on the existing customer managed key.
AnswerB

Using an AWS managed key such as the aws/s3 key automatically satisfies the rotation requirement because AWS KMS rotates AWS managed keys automatically every year (approximately 365 days) without any customer action. These keys are provisioned and managed by AWS, so the restrictive customer key policy on the existing customer managed key does not apply, and you cannot disable or alter their automatic rotation. For S3 server-side encryption with KMS, simply selecting the aws/s3 managed key encrypts objects with a key that is automatically rotated.

Why this answer

AWS managed keys are automatically rotated annually by AWS. This meets the requirement without needing to modify the existing key policy. Option A is wrong because manually rotating the key by creating a new key and updating the S3 bucket policy does not provide automatic rotation and is not the simplest solution.

Option C is wrong because customer managed keys with imported key material do not support automatic rotation. Option D is wrong because the existing key policy does not allow rotation, so enabling automatic rotation on that key would fail; the correct approach is to use an AWS managed key.

← PreviousPage 2 of 3 · 176 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Data Protection questions.