SCS-C02 Management and Security Governance Practice Question
Which AWS service allows you to create and manage encryption keys for your AWS resources?
⚠ Common exam trap
It's easy for candidates to confuse AWS CloudHSM (a dedicated hardware security module) with KMS, not realizing that CloudHSM requires manual management and does not natively integrate with AWS services for automatic encryption, whereas KMS is the fully managed key creation and management service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Key Management Service (KMS)
AWS Key Management Service (KMS) is the managed service designed specifically for creating, storing, and managing encryption keys used to encrypt data across AWS services. It integrates with AWS CloudTrail for auditing key usage and supports symmetric and asymmetric keys, with automatic key rotation and fine-grained access control via IAM and key policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudHSM
Why it's wrong here
AWS CloudHSM provides dedicated hardware security modules that you fully control, but it does not offer a managed key management service with IAM integration, automatic key rotation, or transparent enrollment into AWS services. You must operate the HSM cluster, generate and store keys yourself, and build your own key lifecycle processes. Thus it delivers hardware-rooted cryptography, not the unified key creation and management layer KMS provides.
- ✓
AWS Key Management Service (KMS)
Why this is correct
AWS Key Management Service (KMS) is the managed service purpose-built for creating and managing encryption keys, called customer master keys (CMKs), and data keys. It supports key policies, IAM-based access control, automatic annual rotation, key disabling and deletion, and direct cryptographic operations like encrypt, decrypt, and re-encrypt. KMS also integrates with dozens of AWS services for envelope encryption and records every key usage event in CloudTrail, making it the correct answer.
- ✗
AWS Certificate Manager
Why it's wrong here
AWS Certificate Manager automates the issuance, deployment, and renewal of public and private SSL/TLS certificates used to protect network communications, not to encrypt stored data. It manages certificates as a pair of public and private keys for handshakes, but it does not generate or manage the symmetric data encryption keys or master keys that protect data at rest. So while it does involve key material, its purpose is certificate lifecycle management rather than centralized encryption key management.
- ✗
AWS Secrets Manager
Why it's wrong here
AWS Secrets Manager stores and rotates database credentials, API tokens, and other sensitive strings as secret versions, but it does not create or manage the encryption keys that protect your data. When you use Secrets Manager, it relies on KMS to encrypt secrets with a custom key, yet the service itself offers no key creation, rotation, policy, or cryptographic operation features. Consequently, it is a consumer of KMS, not a replacement for encryption key management.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.