Courseiva

SCS-C02 Management and Security Governance Practice Question

Which AWS service allows you to create and manage encryption keys for your AWS resources?

⚠ Common exam trap

It's easy for candidates to confuse AWS CloudHSM (a dedicated hardware security module) with KMS, not realizing that CloudHSM requires manual management and does not natively integrate with AWS services for automatic encryption, whereas KMS is the fully managed key creation and management service.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Key Management Service (KMS)

AWS Key Management Service (KMS) is the managed service designed specifically for creating, storing, and managing encryption keys used to encrypt data across AWS services. It integrates with AWS CloudTrail for auditing key usage and supports symmetric and asymmetric keys, with automatic key rotation and fine-grained access control via IAM and key policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    AWS CloudHSM provides dedicated hardware security modules that you fully control, but it does not offer a managed key management service with IAM integration, automatic key rotation, or transparent enrollment into AWS services. You must operate the HSM cluster, generate and store keys yourself, and build your own key lifecycle processes. Thus it delivers hardware-rooted cryptography, not the unified key creation and management layer KMS provides.

  • ✓

    AWS Key Management Service (KMS)

    Why this is correct

    AWS Key Management Service (KMS) is the managed service purpose-built for creating and managing encryption keys, called customer master keys (CMKs), and data keys. It supports key policies, IAM-based access control, automatic annual rotation, key disabling and deletion, and direct cryptographic operations like encrypt, decrypt, and re-encrypt. KMS also integrates with dozens of AWS services for envelope encryption and records every key usage event in CloudTrail, making it the correct answer.

  • ✗

    AWS Certificate Manager

    Why it's wrong here

    AWS Certificate Manager automates the issuance, deployment, and renewal of public and private SSL/TLS certificates used to protect network communications, not to encrypt stored data. It manages certificates as a pair of public and private keys for handshakes, but it does not generate or manage the symmetric data encryption keys or master keys that protect data at rest. So while it does involve key material, its purpose is certificate lifecycle management rather than centralized encryption key management.

  • ✗

    AWS Secrets Manager

    Why it's wrong here

    AWS Secrets Manager stores and rotates database credentials, API tokens, and other sensitive strings as secret versions, but it does not create or manage the encryption keys that protect your data. When you use Secrets Manager, it relies on KMS to encrypt secrets with a custom key, yet the service itself offers no key creation, rotation, policy, or cryptographic operation features. Consequently, it is a consumer of KMS, not a replacement for encryption key management.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.