SCS-C02 Data Protection Practice Question
Which TWO of the following are valid options for encrypting data at rest in Amazon S3? (Choose 2.)
⚠ Common exam trap
Many candidates confuse encryption at rest with encryption in transit, leading candidates to select SSL/TLS, or misinterpreting IAM policies as an encryption mechanism, or assuming CloudHSM is a native S3 server-side encryption option rather than a client-side tool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSE-S3
SSE-S3 is correct because it provides server-side encryption where Amazon S3 manages the encryption keys entirely. When you upload an object, S3 encrypts it using AES-256 before writing to disk and decrypts it when you access it, with no additional configuration needed beyond enabling the header `x-amz-server-side-encryption: AES256`.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSL/TLS encryption
Why it's wrong here
SSL/TLS encryption protects data while it is moving between a client and S3 over the network, not data stored in S3 objects at rest. S3 bucket policies can require HTTPS for transport, but SSL/TLS does not encrypt the object bytes on S3's storage media, so it is not a valid at-rest encryption option.
- ✗
IAM policy encryption
Why it's wrong here
IAM policies are JSON documents that define permissions for principals (users, roles, or services) to perform actions on AWS resources; they do not perform any cryptographic operations. IAM conditions can require encryption (e.g., s3:x-amz-server-side-encryption) and can restrict which KMS keys are used, but IAM itself never encrypts data, so this is not a valid encryption method.
- ✓
SSE-S3
Why this is correct
SSE-S3 (Server-Side Encryption with Amazon S3-Managed Keys) is a built-in S3 feature that uses AES-256 to encrypt each object at rest with a unique data key, and the data key itself is encrypted with a regularly rotated master key managed by S3. You enable it by setting the x-amz-server-side-encryption header to AES256 or by applying a bucket default encryption policy, and S3 fully handles the key lifecycle—requiring no customer key management or extra cost.
- ✗
CloudHSM client-side encryption
Why it's wrong here
CloudHSM provides hardware security modules for you to generate and manage your own encryption keys, but it is not a direct S3 encryption option. To encrypt S3 objects with CloudHSM, you would need to implement client-side encryption—encrypting the data in your application using keys from CloudHSM before uploading—which is not a built-in S3 server-side encryption feature and requires significant application-level engineering, so listing it as a direct S3 encryption option is incorrect.
- ✓
SSE-KMS
Why this is correct
SSE-KMS (Server-Side Encryption with AWS Key Management Service) encrypts S3 objects using Customer Master Keys (CMKs) managed by AWS KMS, giving you separate permissions for the CMK, automatic key rotation, and audit trails via CloudTrail. Unlike SSE-S3, SSE-KMS lets you use a customer-managed CMK and enforce conditions such as requiring a specific KMS key, making it a valid at-rest encryption option but one that incurs KMS API costs and additional IAM/KMS policy complexity.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.