Courseiva

CCNA Data Protection Questions

26 of 176 questions · Page 3/3 · Data Protection topic · Answers revealed

151
MCQeasy

A security engineer needs to ensure that all data in transit between an Application Load Balancer and EC2 instances is encrypted using TLS. Which configuration is required?

A.Configure the ALB with an HTTPS listener and the target group with HTTPS protocol.
B.Configure the ALB with an HTTPS listener and the target group with HTTP protocol.
C.Configure the ALB with a TLS listener and the target group with TCP protocol.
D.Configure the ALB with a TCP listener and the target group with HTTP protocol.
AnswerA

To encrypt traffic for the entire path, the ALB must terminate the client-facing TLS connection on an HTTPS listener and then originate a new TLS session to each registered target using an HTTPS target group. This ensures the request is decrypted only inside the ALB and re-encrypted before traversing any network segments to the EC2 instances. Both the listener and the target group certificate must be trusted, and health checks also run over HTTPS, maintaining encryption from edge to backend.

Why this answer

To encrypt data in transit between the Application Load Balancer and EC2 instances, the ALB must have an HTTPS listener and the target group must use HTTPS protocol. This ensures end-to-end TLS encryption from client to ALB and from ALB to EC2 instances. Option A correctly specifies this configuration.

152
MCQeasy

A security engineer needs to ensure that data at rest in an Amazon RDS for PostgreSQL DB instance is encrypted. Which action should the engineer take?

A.Grant the rds:ModifyDBInstance permission to allow encryption toggling.
B.Modify the existing unencrypted DB instance to enable encryption.
C.Enable encryption automatically by enabling automated backups.
D.Create a new DB instance with encryption enabled using the AWS CLI or Console.
AnswerD

To encrypt an existing unencrypted database, you must provision a new DB instance with the StorageEncrypted flag set to true, using either the AWS Management Console, the AWS CLI (--storage-encrypted), or an SDK. You can choose the default aws/rds KMS key or a custom customer-managed key. After the encrypted instance is available, migrate the data from the original instance, for example by restoring an encrypted snapshot or using a logical export/import.

Why this answer

Amazon RDS does not support enabling encryption on an existing unencrypted DB instance; encryption must be specified at creation time. To encrypt data at rest, the engineer must create a new DB instance with encryption enabled (via Console, CLI, or API), then migrate data from the old instance. This is the only supported path for RDS encryption at rest.

Exam trap

SCS-C02 often tests the misconception that RDS encryption can be toggled on an existing instance like an EBS volume — candidates pick 'modify the instance' and miss that StorageEncrypted is immutable at creation.

How to eliminate wrong answers

Option A is wrong because granting rds:ModifyDBInstance does not enable encryption — the ModifyDBInstance API cannot toggle the StorageEncrypted attribute on an existing instance. Option B is wrong because RDS explicitly does not allow modifying an existing unencrypted DB instance to enable encryption; the StorageEncrypted setting is immutable after creation. Option C is wrong because enabling automated backups has no relationship to encryption at rest; backups inherit encryption from the source instance and do not turn on encryption for the primary storage.

153
MCQeasy

A security engineer runs the command shown in the exhibit. What is the outcome?

A.The command fails because AES256 is not a valid algorithm.
B.Default encryption is enabled on the bucket using SSE-S3.
C.Default encryption is enabled on the bucket using SSE-KMS.
D.The command removes default encryption from the bucket.
AnswerB

Seeing `SSEAlgorithm: AES256` in the bucket encryption response means default encryption is enabled with SSE-S3, where Amazon S3 manages the encryption keys. This configuration causes new objects written to the bucket to be automatically encrypted at rest with 256-bit AES using S3-managed keys, and the setting is stored as a bucket-level default rather than applied individually per object.

Why this answer

The command `aws s3api put-bucket-encryption --bucket my-bucket --server-side-encryption-configuration '{"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"AES256"}}]}'` enables default encryption on the bucket using SSE-S3, because `AES256` is the algorithm identifier for SSE-S3 (Amazon S3-managed keys). The command succeeds and sets the default encryption configuration to use server-side encryption with S3-managed keys, which is the standard SSE-S3 behavior.

Exam trap

The trap here is that candidates confuse `AES256` with an invalid algorithm or assume it refers to SSE-KMS, but AWS specifically uses `AES256` as the identifier for SSE-S3, while `aws:kms` is used for SSE-KMS.

How to eliminate wrong answers

Option A is wrong because AES256 is a valid algorithm identifier for SSE-S3; it is not invalid, and the command does not fail due to algorithm validation. Option C is wrong because the algorithm identifier for SSE-KMS is `aws:kms`, not `AES256`; using `AES256` explicitly sets SSE-S3, not SSE-KMS. Option D is wrong because the command adds or updates default encryption, it does not remove it; removing default encryption requires a different API call (e.g., `delete-bucket-encryption`).

154
MCQeasy

A company uses S3 Server Access Logs to audit access to their S3 buckets. The security team wants to ensure that the log files themselves are encrypted at rest using SSE-KMS. Which configuration step is necessary?

A.Use an S3 bucket policy to deny unencrypted uploads to the source bucket
B.Enable default encryption on the source bucket
C.Add a bucket policy on the destination bucket that grants the S3 log delivery service permission to use the KMS key
D.Configure the destination bucket with a lifecycle policy
AnswerC

When the destination bucket for S3 server access logs uses SSE-KMS, the S3 log delivery service (logging.s3.amazonaws.com) must be explicitly allowed to use that KMS key to encrypt the log objects it writes. This is done by adding a bucket policy on the destination bucket that grants kms:GenerateDataKey and kms:Encrypt (as well as s3:PutObject) to the log delivery service. Additionally, the KMS key policy must also allow this service principal to use the key; otherwise, log delivery will fail with an access denied error. This is a required step, so this is the correct answer.

Why this answer

To encrypt S3 Server Access Logs at rest with SSE-KMS, you must add a bucket policy on the destination (log) bucket that grants the S3 log delivery service principal permission to use the KMS key. S3 log delivery writes logs as a service principal, so it needs explicit kms:GenerateDataKey and kms:Decrypt permissions on the key, plus s3:PutObject on the bucket. Without this, log delivery fails when the destination bucket uses SSE-KMS.

Exam trap

SCS-C02 often tests the misconception that enabling default encryption on the source bucket or denying unencrypted uploads secures log files, when the actual requirement is granting the log delivery service permission to use the KMS key on the destination bucket.

How to eliminate wrong answers

Option A is wrong because denying unencrypted uploads to the source bucket does not affect how log files are encrypted in the destination bucket; it addresses source bucket uploads, not log delivery encryption. Option B is wrong because enabling default encryption on the source bucket encrypts objects in the source bucket, not the server access log files delivered to the destination bucket. Option D is wrong because a lifecycle policy manages object transitions and expiration, not encryption or permissions for log delivery; it has no bearing on SSE-KMS for logs.

155
MCQhard

A company is using AWS DMS to migrate data from an on-premises Oracle database to Amazon RDS for PostgreSQL. The data must be encrypted in transit. What should the company do?

A.Use AWS Direct Connect to establish a private connection.
B.Enable SSL on the source and target endpoints in the DMS task.
C.Use AWS KMS to encrypt the data before sending.
D.Set up a VPN connection between the on-premises network and AWS VPC.
AnswerB

AWS DMS has native support for SSL/TLS encryption between the replication instance and both the source and target endpoints. For each endpoint, you can specify an SSL mode (e.g., require for Oracle, SQL Server, and PostgreSQL, or verify-ca for Aurora MySQL) so that all data transferred between the database and DMS is encrypted in transit. With SSL enabled, DMS negotiates an encrypted connection directly with the database engines, ensuring data is protected without relying on additional VPN or network manipulation. This is the most direct and appropriate way to encrypt migration traffic in AWS DMS.

Why this answer

AWS DMS supports SSL/TLS to encrypt data in transit between source and target endpoints. Enabling SSL on both endpoints ensures that the data migration is encrypted over the network. Option A is incorrect because AWS Direct Connect provides a private network connection but does not automatically encrypt traffic; additional encryption like SSL is still required for data in transit.

Option C is incorrect because AWS KMS is used for encryption at rest, not for encrypting data in transit. Option D is incorrect because a VPN connection provides a secure tunnel but is not necessary; DMS can use SSL directly on the endpoints, which is a simpler solution.

156
MCQeasy

A company is using Amazon S3 to store sensitive data. The security team wants to ensure that all data is encrypted in transit between the company's on-premises data center and AWS. Which solution should be used?

A.Use an AWS Site-to-Site VPN with IPsec to encrypt traffic
B.Use AWS CloudHSM to encrypt the data in transit
C.Enable SSE-S3 on the S3 bucket
D.Use AWS KMS to encrypt the data before transmission
AnswerA

An AWS Site-to-Site VPN uses IPsec to encrypt traffic between the on-premises data centre and AWS, satisfying the in-transit encryption requirement for data moving to Amazon S3. IPsec provides cryptographic protection at the network layer, covering all traffic over the connection without application changes.

Why this answer

An AWS Site-to-Site VPN with IPsec is the correct solution because it creates an encrypted tunnel between the on-premises data center and AWS, ensuring all data in transit is protected. IPsec operates at the network layer (Layer 3) and encrypts the entire IP packet, providing confidentiality and integrity for data moving over the public internet. This directly addresses the requirement to encrypt data in transit between the two environments.

Exam trap

The trap here is that candidates often confuse encryption at rest (SSE-S3, KMS) with encryption in transit, and assume that encrypting data before sending it (e.g., with KMS) automatically secures the transmission channel, when in fact a transport-layer encryption mechanism like IPsec or TLS is required to protect data during transit.

How to eliminate wrong answers

Option B is wrong because AWS CloudHSM is a hardware security module used for key storage and cryptographic operations, not for encrypting data in transit; it does not provide network-level encryption between on-premises and AWS. Option C is wrong because SSE-S3 (Server-Side Encryption with S3-Managed Keys) encrypts data at rest in S3, not data in transit; it has no effect on traffic between the on-premises data center and AWS. Option D is wrong because AWS KMS is a key management service that can be used to encrypt data before transmission, but it does not provide a secure tunnel or protocol-level encryption for the data in transit; the data would still be sent over the internet in an unencrypted form unless a transport encryption mechanism like TLS or IPsec is also applied.

157
MCQhard

A company is using AWS KMS to encrypt data in Amazon S3. The security team discovers that an S3 bucket has a bucket policy that allows s3:PutObject without requiring encryption. What is the risk?

A.The KMS key can be used by unauthorized users
B.Data can be downloaded without authentication
C.Data in transit is not encrypted
D.Data can be uploaded without encryption at rest
AnswerD

If the policy permits PutObject without requiring the s3:x-amz-server-side-encryption header or a condition that forces encryption, clients can upload objects in plaintext to S3. Although the company uses KMS for encryption, that KMS key is only used when the upload explicitly requests SSE-KMS or the bucket has default encryption and the client doesn't override it. Without an explicit Deny for unencrypted uploads, some objects may remain unencrypted at rest, defeating the company's stated security intent.

Why this answer

When the bucket policy allows s3:PutObject without requiring encryption (e.g., x-amz-server-side-encryption header), data can be uploaded as plaintext and stored without encryption at rest, violating data protection requirements. Option A is incorrect because the KMS key usage is controlled by KMS policies, not the bucket policy. Option B is incorrect because authentication is required for PutObject, but encryption is not enforced.

Option C is incorrect because encryption in transit (TLS) is separate from encryption at rest.

158
MCQmedium

A company is using AWS KMS to encrypt data at rest in Amazon S3. The security team wants to ensure that only a specific IAM role can decrypt objects in a particular S3 bucket. Which policy should be attached to the KMS key to enforce this restriction?

A.KMS grant that gives the IAM role decrypt permissions for the key
B.IAM policy attached to the role that allows kms:Decrypt for the key
C.S3 bucket policy that denies decrypt unless the requester is the specific IAM role
D.KMS key policy with a condition that the principal must be the specific IAM role
AnswerD

A KMS key policy that explicitly lists the IAM role as Principal, optionally with a condition like aws:PrincipalArn, correctly restricts kms:Decrypt to that role. Key policies are the authoritative control for a KMS key, and when they grant access to a specific principal, IAM policies are not required for that identity to decrypt. This is the recommended approach when the desired access is limited to a particular role and you want the key policy to be self-contained and auditable. Since the key policy is evaluated first and any IAM allow is subordinate to it, this configuration unambiguously enforces the intended restriction.

Why this answer

KMS key policies are the main mechanism to control access to KMS keys. By specifying the IAM role as the principal in a key policy statement for the kms:Decrypt action, only that role can decrypt using the key. Option A is incorrect because KMS grants are intended for temporary or cross-account access and are not the best practice for permanent control.

Option B is incorrect because IAM policies alone are not sufficient if the key policy does not allow the role; both policies must align. Option C is incorrect because S3 bucket policies control access to S3 operations, not KMS decryption permissions directly.

159
MCQhard

A company uses AWS KMS to encrypt EBS volumes. They want to ensure that the key used for EBS encryption is not shared across different AWS accounts. Which feature should they use?

A.Use a CloudHSM custom key store.
B.Use the key's alias to restrict access.
C.Enable automatic key rotation.
D.Configure the key policy to deny access to any principal from another AWS account.
AnswerD

Configure the key policy with a Deny statement that uses the aws:PrincipalAccount condition to block any principal whose account ID does not match the expected account. Since the key policy is the authoritative resource-based policy for the KMS key, an explicit deny overrides any IAM permissions in another account and prevents cross-account EBS volume or snapshot sharing. This directly enforces the desired account boundary.

Why this answer

AWS KMS key policies can explicitly deny access to principals from other AWS accounts by using the `aws:SourceAccount` or `aws:SourceArn` condition keys, or by specifying a `Deny` statement with a condition that checks the account ID. This ensures that the KMS key used for EBS encryption cannot be used by any IAM principal or role from a different AWS account, preventing cross-account key sharing.

Exam trap

The trap here is that candidates often confuse key rotation (Option C) or aliases (Option B) with access control, or assume that CloudHSM (Option A) inherently isolates keys across accounts, when in fact only the key policy can enforce account-level restrictions.

How to eliminate wrong answers

Option A is wrong because CloudHSM custom key stores provide a hardware security module (HSM) for key storage but do not inherently restrict cross-account access; the key policy must still be configured to deny other accounts. Option B is wrong because a key's alias is simply a friendly name for the key and does not enforce any access control; aliases are not evaluated in authorization decisions. Option C is wrong because automatic key rotation only changes the cryptographic material of the key over time (typically annually) and has no effect on cross-account access permissions.

160
Multi-Selectmedium

A company needs to enforce encryption in transit for all traffic between an Amazon EC2 instance and an Amazon RDS database. Which TWO steps should be taken?

Select 2 answers
A.Enable TLS on the RDS database and configure the database to require encrypted connections.
B.Configure security groups to allow traffic only on port 3306 (MySQL) or 5432 (PostgreSQL).
C.Set up a VPN connection between the EC2 instance and the RDS database.
D.Enable encryption at rest on the RDS instance.
E.Configure the application to connect using TLS/SSL.
AnswersA, E

Setting `require_secure_transport=1` on MySQL or `rds.force_ssl=1` on PostgreSQL in the RDS parameter group makes the server reject any non-TLS connection, explicitly enforcing encryption at the database layer. This server-side configuration is authoritative: only TLS-enabled clients with the appropriate CA certificate can connect, so plaintext traffic is refused regardless of client-side settings.

Why this answer

Option A is correct because enforcing encryption in transit for RDS requires enabling TLS on the DB instance and setting the parameter group so the database requires SSL/TLS connections (for example, MySQL's require_secure_transport or PostgreSQL's rds.force_ssl), which rejects unencrypted client sessions. Option E is correct because the client side must actually negotiate TLS: the application on the EC2 instance has to connect using SSL/TLS, typically by supplying the RDS CA certificate (rds-ca-rsa2048-g1 or similar) and using the appropriate driver parameters such as sslmode=require for PostgreSQL or ssl-mode=REQUIRED for MySQL. Option B is not correct because security groups only control network reachability on ports 3306/5432 and do not provide or enforce encryption.

Option C is not correct because a VPN encrypts traffic at the network layer between networks but is not the mechanism used to enforce TLS between an EC2 instance and an RDS endpoint, and RDS TLS is the supported approach. Option D is not correct because encryption at rest protects stored data via KMS and does not address data in transit between the EC2 instance and the database.

Exam trap

SCS-C02 often tests the distinction between encryption at rest (KMS, option D) and encryption in transit (TLS, options A/E); candidates who see 'encrypt' and grab the KMS/at-rest answer miss that the question specifies traffic between EC2 and RDS.

161
Multi-Selecteasy

A company needs to protect data at rest in Amazon S3. Which THREE server-side encryption mechanisms can be used to encrypt objects stored in S3?

Select 3 answers
A.Server-Side Encryption with S3-Managed Keys (SSE-S3)
B.Server-Side Encryption with AWS KMS-Managed Keys (SSE-KMS)
C.Client-Side Encryption
D.Server-Side Encryption with IAM-Managed Keys (SSE-IAM)
E.Server-Side Encryption with Customer-Provided Keys (SSE-C)
AnswersA, B, E

SSE-S3 encrypts each object with a unique key, itself encrypted by a regularly rotated root key managed entirely by AWS, using AES-256. It satisfies data-at-rest protection with no key management overhead, applied by default to every uploaded object.

Why this answer

The question asks for server-side encryption mechanisms for S3 objects, and three options qualify. Option A, SSE-S3, is correct because Amazon S3 manages the encryption keys and applies AES-256 encryption to objects at rest, requiring only the x-amz-server-side-encryption: AES256 header. Option B, SSE-KMS, is correct because it uses AWS KMS customer master keys (CMKs) to generate and manage data keys, providing auditability via CloudTrail and granular key policies.

Option E, SSE-C, is correct because the customer supplies their own encryption key with each request, and S3 performs the encryption/decryption server-side without storing the key. Option C, Client-Side Encryption, is not a server-side mechanism since data is encrypted before it reaches S3. Option D, SSE-IAM, does not exist as an S3 encryption option; IAM manages permissions, not encryption keys.

Exam trap

SCS-C02 often tests whether candidates confuse client-side encryption with server-side options or invent non-existent mechanisms like SSE-IAM — the trap is picking 'client-side' as a server-side method or selecting a fabricated acronym.

162
MCQeasy

A company wants to encrypt data in transit between an Application Load Balancer (ALB) and its targets. Which configuration should be used?

A.Configure the ALB with a TCP listener and use Network Load Balancer.
B.Configure the ALB with an HTTPS listener and use HTTPS as the protocol for the target group.
C.Configure the ALB security group to allow only encrypted traffic.
D.Configure the ALB with an HTTP listener and use a security group to enforce encryption.
AnswerB

Configuring an HTTPS listener and an HTTPS target group encrypts traffic at both hops, including the ALB-to-target leg. This satisfies the requirement for in-transit encryption between load balancer and targets, since the default HTTP target protocol leaves that segment unencrypted.

Why this answer

To encrypt data in transit between an ALB and its targets, you must configure the ALB listener to use HTTPS and set the target group protocol to HTTPS. This ensures that traffic from the ALB to the targets is encrypted using TLS. The ALB terminates the client-side TLS and establishes a new TLS connection to the targets.

Exam trap

SCS-C02 often tests the difference between encryption in transit and network security controls, and candidates may incorrectly assume that security groups can enforce encryption or confuse ALB with NLB capabilities.

How to eliminate wrong answers

Option A is wrong because ALBs do not support TCP listeners; TCP listeners are for Network Load Balancers (NLB). Also, using an NLB would not meet the requirement of an ALB. Option C is wrong because security groups control network access, not encryption; they cannot enforce encryption.

Option D is wrong because an HTTP listener does not encrypt traffic, and security groups cannot enforce encryption; they only filter traffic based on IP, port, and protocol.

163
MCQhard

A company is designing a data protection strategy for sensitive data stored in Amazon S3. Compliance requirements mandate that all data be encrypted at rest using customer-provided keys (SSE-C). Which solution meets the requirements with minimal operational overhead?

A.Use server-side encryption with Amazon S3 managed keys (SSE-S3) and enable bucket versioning.
B.Use client-side encryption with the AWS Encryption SDK and store keys in the application configuration.
C.Use server-side encryption with customer-provided keys (SSE-C) and store the keys in AWS Secrets Manager.
D.Use server-side encryption with AWS KMS managed keys (SSE-KMS) and enable automatic key rotation.
AnswerC

SSE-C allows you to provide your own encryption keys in S3 API request headers, and S3 uses them for AES-256 encryption/decryption but never stores the key material, giving you full control over the key lifecycle. Storing those keys in AWS Secrets Manager adds secure storage, centralizes access control, and enables programmatic retrieval for uploads/downloads while keeping the key material customer-owned. This directly satisfies a bring-your-own-key requirement without the overhead of client-side encryption, though you must use HTTPS and supply the key on every request.

Why this answer

Server-side encryption with customer-provided keys (SSE-C) allows the customer to supply their own encryption keys while AWS manages the encryption/decryption process, meeting compliance requirements with minimal operational overhead. Storing the keys in AWS Secrets Manager adds convenience and security. Option A is incorrect because SSE-S3 uses AWS-managed keys, not customer-provided keys.

Option B is incorrect because client-side encryption with the AWS Encryption SDK requires the application to handle encryption, increasing overhead and complexity, and it does not use SSE-C. Option D is incorrect because SSE-KMS uses AWS KMS managed keys, not customer-provided keys, even if key rotation is enabled.

164
MCQmedium

A company uses AWS KMS to encrypt data in Amazon RDS. The security team needs to ensure that the KMS key cannot be deleted accidentally. Which action should be taken?

A.Create an alias for the key.
B.Enable automatic key rotation.
C.Add a statement to the key policy that denies the kms:ScheduleKeyDeletion action.
D.Use a multi-Region key.
AnswerC

A key policy is the resource-based policy that governs access to a KMS key. Adding an explicit Deny statement for the kms:ScheduleKeyDeletion action prevents any principal—including IAM users, roles, or the account root—from scheduling the key for deletion, because an explicit Deny overrides any Allow. This makes the key effectively non-deletable through the normal API, assuming the key policy itself cannot be altered by unauthorized principals.

Why this answer

A key policy statement that explicitly denies kms:ScheduleKeyDeletion prevents any principal from scheduling the key for deletion, which is the strongest guard against accidental deletion. Explicit deny in a key policy overrides any allow, so even administrators cannot schedule deletion.

Exam trap

SCS-C02 often tests the misconception that key rotation or aliases protect against deletion, when the only reliable protection is an explicit Deny on kms:ScheduleKeyDeletion in the key policy.

How to eliminate wrong answers

Option A is wrong because an alias is just a friendly name for a key; it does not prevent deletion and can be reassigned. Option B is wrong because automatic key rotation rotates the backing key material but does not prevent the key from being scheduled for deletion. Option D is wrong because a multi-Region key is a replication feature for cross-Region use; it does not protect against deletion and in fact deleting a multi-Region primary key affects replicas.

165
Multi-Selecthard

A company uses AWS CloudTrail to log API calls. They want to ensure that log files are encrypted at rest and that integrity is verified. Which TWO services can be used together to achieve this?

Select 2 answers
A.S3 Inventory
B.AWS CloudHSM
C.CloudTrail log file integrity validation
D.AWS KMS to encrypt the log files
E.S3 MFA Delete
AnswersC, D

CloudTrail log file integrity validation delivers a tamper-evident chain by hashing each log file with SHA-256, digitally signing the digest with a private key, and storing those digest files in the same delivery bucket. During validation, CloudTrail compares file hashes and signatures, so any modification, deletion, or replacement of delivered logs is detected, even if someone has access to the bucket. This directly addresses the requirement to prove that CloudTrail logs have not been altered.

Why this answer

CloudTrail log file integrity validation (option C) provides a built-in mechanism to verify that log files have not been modified, deleted, or tampered with after delivery. It uses SHA-256 hashing and digital signatures (based on RSA) to create a digest file that can be independently validated. AWS KMS (option D) allows you to encrypt CloudTrail log files at rest using server-side encryption (SSE-KMS), ensuring that the logs are stored in an encrypted format.

Together, they meet both the encryption-at-rest and integrity verification requirements.

Exam trap

The trap here is that candidates often confuse AWS CloudHSM with AWS KMS, thinking CloudHSM can directly encrypt CloudTrail logs, but CloudTrail only supports encryption via S3-managed keys (SSE-S3) or KMS keys (SSE-KMS), not CloudHSM, and integrity validation is a separate built-in feature of CloudTrail itself.

166
MCQeasy

A company needs to ensure that data in transit between an on-premises data center and Amazon S3 is encrypted. The data will be transferred using HTTPS. What additional step should be taken to ensure the encryption is enforced?

A.Use AWS KMS to require encryption in transit
B.Enable S3 Transfer Acceleration
C.Add a bucket policy that denies requests where aws:SecureTransport is false
D.Use Amazon CloudFront with HTTPS only
AnswerC

Adding a bucket policy with a condition that denies requests when `aws:SecureTransport` is `false` enforces HTTPS by rejecting any HTTP or unencrypted requests at the S3 API level. This satisfies the stem’s requirement to ensure encryption is enforced for data in transit, as the policy explicitly blocks non-HTTPS traffic regardless of the client’s protocol choice.

Why this answer

The correct answer is C because S3 bucket policies can enforce encryption in transit by denying any request where the aws:SecureTransport condition key is false. This ensures that only HTTPS (TLS) requests are allowed, effectively blocking HTTP access. Since the data is already being transferred over HTTPS, adding this policy guarantees that encryption in transit is enforced and cannot be bypassed.

Exam trap

SCS-C02 often tests the difference between encryption at rest and encryption in transit, and candidates may confuse AWS KMS (which is for at-rest encryption) with mechanisms that enforce in-transit encryption, leading them to pick option A.

How to eliminate wrong answers

Option A is wrong because AWS KMS is used for encryption at rest (server-side encryption) and does not enforce encryption in transit; KMS keys encrypt data on disk, not over the wire. Option B is wrong because S3 Transfer Acceleration speeds up transfers using AWS edge locations but does not enforce encryption; it can be used with HTTP or HTTPS. Option D is wrong because CloudFront with HTTPS only encrypts data between the client and CloudFront, but the origin connection to S3 might still use HTTP unless separately configured; moreover, the question specifies direct HTTPS transfer to S3, so CloudFront is unnecessary and does not enforce encryption for direct S3 access.

167
MCQeasy

A company needs to protect data at rest on Amazon EBS volumes attached to EC2 instances. Which solution provides the most control over the encryption keys?

A.Use a customer managed KMS key with EBS encryption.
B.Encrypt data using client-side encryption before writing to EBS.
C.Use an AWS managed KMS key for EBS encryption.
D.Enable EBS encryption by default in the account.
AnswerA

Using a customer managed KMS key with EBS encryption is the correct approach because it gives you full control over the key lifecycle, key policy, and permissions, allowing you to restrict access to specific principals or services. EBS encryption uses envelope encryption where a CMK generates a data key to encrypt the volume, and you can audit key usage through CloudTrail. This provides a native, seamless encryption solution for data at rest without requiring application changes, and it supports compliance requirements that mandate customer-controlled keys.

Why this answer

A customer managed KMS key gives the account owner full control over the key policy, rotation, grants, and deletion, which is the maximum control available for EBS encryption at rest. AWS managed keys (aws/ebs) are controlled by AWS and cannot be customized or have their policies modified by the customer. Enabling EBS encryption by default only sets a default key but does not by itself provide the most control.

Client-side encryption is a different layer and does not address EBS-native encryption key control.

Exam trap

SCS-C02 often tests the distinction between AWS managed and customer managed KMS keys; candidates incorrectly assume that enabling EBS encryption by default or using an AWS managed key provides the same level of control as a customer managed key.

How to eliminate wrong answers

Option B is wrong because client-side encryption occurs before data reaches EBS and does not leverage EBS/KMS key management; it provides confidentiality but not the granular KMS key control the question asks for. Option C is wrong because AWS managed KMS keys are owned and managed by AWS, with fixed key policies and no customer ability to rotate, restrict, or audit key usage beyond CloudTrail. Option D is wrong because enabling EBS encryption by default simply ensures new volumes are encrypted with a default key (often the AWS managed key) and does not grant additional key control.

168
Multi-Selectmedium

A company uses AWS KMS to encrypt data in Amazon RDS. The security team wants to ensure that the KMS key can be used only by specific IAM roles and that all usage of the key is logged. Which TWO actions should the team take?

Select 2 answers
A.Apply an S3 bucket policy to the RDS automated backup bucket
B.Enable automatic key rotation
C.Enable AWS CloudTrail to log KMS API calls
D.Modify the key policy to grant kms:Encrypt and kms:Decrypt only to the required IAM roles
E.Create a cross-account key policy to allow all IAM roles in the account
AnswersC, D

Enabling AWS CloudTrail to log KMS API calls provides a detailed audit trail of every kms:Encrypt, kms:Decrypt, GenerateDataKey, and other KMS operation, including the IAM principal, source IP, and request timestamp. This is a detective control that lets security engineers monitor and investigate who is using the key and when, which is the correct approach when the goal is visibility into KMS usage. CloudTrail does not prevent or allow operations, so it complements, rather than replaces, access-control policies.

Why this answer

To restrict KMS key usage to specific IAM roles, the key policy must be modified to grant only those roles the kms:Encrypt and kms:Decrypt permissions (option D). To log all usage of the key, enable AWS CloudTrail to capture KMS API calls (option C). Option A is incorrect because an S3 bucket policy does not control KMS key usage.

Option B is incorrect because key rotation does not restrict access. Option E is incorrect because cross-account access is not specified as a requirement.

169
MCQmedium

A company stores sensitive data in an Amazon S3 bucket. They want to ensure that data is encrypted in transit when accessed from the internet. Which policy should they attach to the bucket?

A.{"Effect": "Deny", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringNotEquals": {"aws:SourceVpc": "vpc-12345"}}}
B.{"Effect": "Allow", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"Bool": {"aws:SecureTransport": "false"}}}
C.{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"Bool": {"aws:SecureTransport": "false"}}}
D.{"Effect": "Deny", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"IpAddress": {"aws:SourceIp": "0.0.0.0/0"}}}
AnswerC

This is the correct policy because it denies all S3 actions (s3:*) when the request is not using secure transport, as indicated by aws:SecureTransport being false. By using Deny on the entire action set and the Bool condition, it ensures that any request over HTTP is rejected, while HTTPS requests remain unaffected. This is the standard AWS recommended pattern for enforcing encryption in transit on an S3 bucket.

Why this answer

It uses a Deny effect with the aws:SecureTransport condition set to 'false', which explicitly blocks any request that does not use HTTPS/TLS. This ensures that all S3 operations (s3:*) on the bucket objects require encryption in transit, as any HTTP request will be denied. The Deny effect overrides any Allow, making this a robust policy to enforce encrypted access from the internet.

Exam trap

The trap here is that candidates often choose an Allow policy (like Option B) thinking it will permit only encrypted traffic, but they forget that an Allow with a condition does not block unencrypted requests—only a Deny can explicitly block them, and the condition must be inverted (e.g., 'false' to block HTTP).

How to eliminate wrong answers

Option A is wrong because it restricts access based on the source VPC (aws:SourceVpc), which controls network origin but does not enforce encryption in transit; requests from outside the VPC could still use HTTP. Option B is wrong because it uses an Allow effect with aws:SecureTransport set to 'false', which would allow only unencrypted requests (the opposite of the requirement) and also fails to deny encrypted requests. Option D is wrong because it denies requests from all IP addresses (0.0.0.0/0), which would block all internet traffic regardless of encryption, rather than selectively enforcing HTTPS.

170
MCQeasy

A security engineer needs to ensure that all data stored in a new Amazon DynamoDB table is encrypted at rest using a key that the company can manage, audit, and rotate. The company also wants to receive alerts if the key is used in an unauthorized way. Which solution meets these requirements with the LEAST operational effort?

A.Use AWS KMS customer managed keys with DynamoDB encryption at rest.
B.Use AWS CloudHSM to generate and store keys, and integrate with DynamoDB encryption.
C.Enable DynamoDB encryption at rest with AWS owned keys.
D.Implement client-side encryption using a key stored in AWS Secrets Manager.
AnswerA

DynamoDB encryption at rest integrates with AWS KMS, allowing the use of customer managed keys. This provides control over key policies, enables auditing via AWS CloudTrail, and supports automatic rotation. It requires minimal operational effort because DynamoDB manages the encryption and decryption transparently, and KMS handles key management, meeting all requirements.

Why this answer

AWS KMS customer managed keys with DynamoDB encryption at rest provide customer control, auditability through CloudTrail, and automatic rotation with minimal effort. AWS owned keys lack customer control and auditing. Client-side encryption with Secrets Manager or CloudHSM introduces extra operational burden and does not integrate natively with DynamoDB encryption at rest.

Exam trap

The trap here is thinking that AWS owned keys provide customer management, when they are fully managed by AWS and cannot be audited or rotated by the customer.

171
MCQeasy

A company is using Amazon S3 to store confidential documents. They want to ensure that all data is encrypted in transit between the S3 bucket and their on-premises application. Which of the following should be enforced?

A.Add a bucket policy that denies access unless 'aws:SecureTransport' is true.
B.Use Amazon CloudFront with a custom origin pointing to the S3 bucket.
C.Use a VPC endpoint for S3.
D.Enable default encryption (SSE-S3) on the bucket.
AnswerA

The aws:SecureTransport condition key evaluates the request's protocol, so denying when it is false blocks any plain HTTP request to the bucket. This enforces TLS for data in transit between the on-premises application and S3.

Why this answer

A bucket policy that denies requests unless `aws:SecureTransport` is true enforces TLS for all access to the bucket, including from on-premises applications. This is the canonical AWS pattern for requiring encryption in transit to S3. The other options either do not enforce TLS or address different concerns (encryption at rest, network path).

Exam trap

SCS-C02 often tests whether candidates conflate encryption at rest (SSE-S3) with encryption in transit, or assume a VPC endpoint enforces TLS — only the `aws:SecureTransport` bucket policy condition actually does.

How to eliminate wrong answers

Option B is wrong because CloudFront with a custom origin does not by itself enforce TLS between the origin (S3) and the on-premises application — it only affects the client-to-CloudFront leg and does not guarantee HTTPS to S3. Option C is wrong because a VPC endpoint provides private network connectivity from a VPC to S3 but does not enforce TLS; traffic over a VPC endpoint can still be HTTP unless the bucket policy requires SecureTransport. Option D is wrong because SSE-S3 provides encryption at rest, not in transit, and does nothing to require TLS for data moving between the bucket and on-premises systems.

172
MCQhard

A company is designing a data protection strategy for an Amazon RDS for MySQL database. The database is 2 TB in size and stores financial data. The compliance team requires that database snapshots be encrypted at rest and that encryption keys be rotated every year. Which solution meets these requirements with the LEAST operational overhead?

A.Copy each snapshot to a new snapshot encrypted with a new KMS key
B.Export snapshots to S3 and use S3 Batch Operations to re-encrypt them
C.Use a different KMS key for each snapshot and rotate the key manually
D.Enable automatic key rotation in AWS KMS for the KMS key used for RDS encryption
AnswerD

Enabling automatic key rotation in AWS KMS for the customer-managed KMS key used by RDS meets the data protection requirement with minimal operational overhead. AWS KMS rotates the cryptographic backing key each year while keeping the same KMS key ID, so the RDS instance, its storage, and all future snapshots continue using the same key reference with zero manual intervention. Existing data remains decryptable via the previous backing key, and new writes automatically use the new backing key, providing continuous protection.

Why this answer

Enabling automatic key rotation in AWS KMS for the KMS key used for RDS encryption meets the compliance requirement of yearly key rotation without any manual effort. RDS automatically uses the rotated key for new snapshots, and existing snapshots remain encrypted with the original key but can be decrypted with the new key as KMS maintains the key hierarchy. Option A is wrong because copying snapshots to re-encrypt with a new KMS key requires manual scripting and adds operational overhead.

Option B is wrong because exporting snapshots to S3 and using S3 Batch Operations is complex and unnecessary. Option C is wrong because using a different KMS key for each snapshot and manually rotating adds significant operational overhead and does not leverage the automatic rotation capability of KMS.

173
MCQhard

A security engineer is configuring AWS KMS for a multi-Region application that uses Amazon S3 and Amazon RDS in us-east-1 and eu-west-1. The company requires that encryption keys be available in both Regions and that data encrypted in one Region can be decrypted in the other without re-encrypting. The company also wants to minimize latency for cryptographic operations. Which solution meets these requirements?

A.Use an AWS CloudHSM cluster in each Region and replicate keys between them.
B.Enable automatic key rotation on a single KMS key and use it in both Regions.
C.Use AWS KMS multi-Region keys with a primary key in us-east-1 and a replica in eu-west-1.
D.Create a customer managed key in us-east-1 and grant cross-Region access to principals in eu-west-1.
AnswerC

Multi-Region keys are a set of interoperable KMS keys in different Regions that share the same key material and key ID. They allow data encrypted in one Region to be decrypted in another without re-encryption. Creating a primary key and a replica in the second Region provides availability and low-latency access, meeting all requirements.

Why this answer

AWS KMS multi-Region keys allow the same key material to be used in multiple Regions, so data encrypted in one Region can be decrypted in another without re-encryption. Creating a primary key and a replica in the second Region provides availability and low-latency access. Single-Region keys, CloudHSM replication, and rotation do not meet the cross-Region decryption requirement.

Exam trap

The trap here is assuming that a single KMS key can be used across Regions, when KMS keys are strictly regional and multi-Region keys are required for cross-Region decryption.

174
MCQmedium

A company has a requirement to automatically rotate encryption keys for Amazon EBS volumes every 90 days. The EBS volumes are encrypted using AWS KMS. What is the simplest way to meet this requirement?

A.Use AWS Secrets Manager to rotate the KMS key automatically.
B.Create a new KMS key every 90 days and re-encrypt volumes using a script.
C.Switch to client-side encryption and rotate keys manually.
D.Enable automatic key rotation on the existing KMS key.
AnswerB

To satisfy a 90-day rotation requirement, you must perform manual key rotation by creating a new KMS key every 90 days and then re-encrypting your EBS volumes with that new key. A typical scripted approach creates an encrypted snapshot of each volume using the new key, creates a new volume from that snapshot, and attaches it to the instance after detaching the old volume. This changes the actual key ID and re-encrypts the volume data, which is the only way to meet a sub-yearly rotation schedule because KMS automatic rotation only occurs every year.

Why this answer

KMS automatic key rotation creates new backing keys yearly, not every 90 days. To meet the 90-day rotation requirement, you must manually create a new KMS key every 90 days and then re-encrypt the EBS volumes (e.g., by taking a snapshot, copying it with the new key, and restoring). Option A is incorrect because AWS Secrets Manager manages secrets, not KMS keys; it cannot rotate KMS keys.

Option C is incorrect because client-side encryption would require managing keys outside of KMS, which adds complexity and does not meet the requirement of using AWS KMS. Option D is incorrect because automatic key rotation on the existing KMS key only rotates the backing key once per year, not every 90 days.

175
Multi-Selecthard

Which THREE of the following are valid key management features of AWS KMS? (Choose THREE.)

Select 3 answers
A.Importing key material
B.Key policies
C.SSL certificate management
D.Password generation
E.Automatic key rotation
AnswersA, B, E

KMS allows you to create a customer managed key with your own cryptographic key material rather than using AWS-generated bytes. This import capability is essential for organizations needing to retain exclusive control over key material to satisfy regulatory or compliance mandates. However, once you import key material, you cannot enable automatic rotation of that KMS key, so you must plan for manual rotation or replacement.

Why this answer

AWS KMS allows you to import your own key material (BYOK) for use with KMS keys, which is a valid key management feature. This is done via the 'ImportKeyMaterial' API, enabling you to create a KMS key with no key material and then upload your own symmetric key material. This feature is essential for meeting compliance requirements that mandate control over the key material lifecycle.

Exam trap

The trap here is that candidates may confuse KMS's key management capabilities with other AWS security services, mistakenly thinking KMS handles SSL certificates or password generation, when in reality those are separate services with distinct purposes.

176
MCQeasy

A company wants to ensure that all data transferred between its on-premises data center and AWS is encrypted in transit. Which AWS service should be used to meet this requirement?

A.Amazon CloudFront
B.AWS Transit Gateway
C.AWS Direct Connect
D.AWS Site-to-Site VPN
AnswerD

AWS Site-to-Site VPN is the correct service because it builds an encrypted IPsec tunnel between a customer gateway and a virtual private gateway, encrypting all traffic in transit across the public internet. It uses IKE for key exchange and IPsec protocols like ESP to provide confidentiality and integrity for every packet. This directly satisfies the requirement to ensure all data transferred between the company's network and AWS is protected.

Why this answer

AWS Site-to-Site VPN encrypts data in transit between an on-premises network and AWS by establishing IPsec tunnels over the public internet, satisfying the requirement for encryption in transit. It uses IKE for key exchange and IPsec ESP for payload encryption, providing confidentiality and integrity for all traffic traversing the VPN connection. This is the standard AWS service for encrypted hybrid connectivity.

Exam trap

SCS-C02 often tests the misconception that AWS Direct Connect encrypts traffic by default — it does not, and candidates must recognize that Site-to-Site VPN (or MACsec on Direct Connect) is required for encryption in transit.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront is a content delivery network that terminates TLS at edge locations for HTTP(S) content — it does not provide encrypted site-to-site connectivity between on-premises and AWS. Option B is wrong because AWS Transit Gateway is a network hub that routes traffic between VPCs and on-premises connections, but by itself it does not encrypt traffic; it can carry unencrypted Direct Connect or VPN traffic. Option C is wrong because AWS Direct Connect is a dedicated private fiber connection that is not encrypted by default — it provides private connectivity but requires a VPN overlay or MACsec for encryption in transit.

← PreviousPage 3 of 3 · 176 questions total

Ready to test yourself?

Try a timed practice session using only Data Protection questions.