Courseiva
Data Protection →easyMultiple Select

SCS-C02 Data Protection Practice Question

Which TWO of the following are valid options for encrypting data at rest in Amazon S3? (Choose 2.)

⚠ Common exam trap

Many candidates confuse encryption at rest with encryption in transit, leading candidates to select SSL/TLS, or misinterpreting IAM policies as an encryption mechanism, or assuming CloudHSM is a native S3 server-side encryption option rather than a client-side tool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSE-S3

SSE-S3 is correct because it provides server-side encryption where Amazon S3 manages the encryption keys entirely. When you upload an object, S3 encrypts it using AES-256 before writing to disk and decrypts it when you access it, with no additional configuration needed beyond enabling the header `x-amz-server-side-encryption: AES256`.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSL/TLS encryption

    Why it's wrong here

    SSL/TLS encryption protects data while it is moving between a client and S3 over the network, not data stored in S3 objects at rest. S3 bucket policies can require HTTPS for transport, but SSL/TLS does not encrypt the object bytes on S3's storage media, so it is not a valid at-rest encryption option.

  • ✗

    IAM policy encryption

    Why it's wrong here

    IAM policies are JSON documents that define permissions for principals (users, roles, or services) to perform actions on AWS resources; they do not perform any cryptographic operations. IAM conditions can require encryption (e.g., s3:x-amz-server-side-encryption) and can restrict which KMS keys are used, but IAM itself never encrypts data, so this is not a valid encryption method.

  • ✓

    SSE-S3

    Why this is correct

    SSE-S3 (Server-Side Encryption with Amazon S3-Managed Keys) is a built-in S3 feature that uses AES-256 to encrypt each object at rest with a unique data key, and the data key itself is encrypted with a regularly rotated master key managed by S3. You enable it by setting the x-amz-server-side-encryption header to AES256 or by applying a bucket default encryption policy, and S3 fully handles the key lifecycle—requiring no customer key management or extra cost.

  • ✗

    CloudHSM client-side encryption

    Why it's wrong here

    CloudHSM provides hardware security modules for you to generate and manage your own encryption keys, but it is not a direct S3 encryption option. To encrypt S3 objects with CloudHSM, you would need to implement client-side encryption—encrypting the data in your application using keys from CloudHSM before uploading—which is not a built-in S3 server-side encryption feature and requires significant application-level engineering, so listing it as a direct S3 encryption option is incorrect.

  • ✓

    SSE-KMS

    Why this is correct

    SSE-KMS (Server-Side Encryption with AWS Key Management Service) encrypts S3 objects using Customer Master Keys (CMKs) managed by AWS KMS, giving you separate permissions for the CMK, automatic key rotation, and audit trails via CloudTrail. Unlike SSE-S3, SSE-KMS lets you use a customer-managed CMK and enforce conditions such as requiring a specific KMS key, making it a valid at-rest encryption option but one that incurs KMS API costs and additional IAM/KMS policy complexity.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.