SCS-C02 Data Protection Practice Question
Which TWO of the following are valid ways to enforce encryption at rest for data in Amazon S3? (Choose TWO.)
⚠ Common exam trap
SCS-C02 often tests the difference between encryption in transit and at rest; candidates may select SSL/TLS or IAM policies, but those do not enforce encryption at rest.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use SSE-KMS
SSE-KMS (option D) is correct because it enforces server-side encryption at rest by having Amazon S3 encrypt objects with keys managed in AWS KMS, providing envelope encryption and auditability via CloudTrail. SSE-C (option E) is also correct because it enforces server-side encryption at rest using a customer-provided encryption key that S3 applies to the object, so data is stored encrypted on disk. Option A (SSL/TLS) is incorrect because it only protects data in transit between the client and S3, not data at rest. Option B (IAM policies) is incorrect because IAM controls authorization and permissions, not the encryption of stored objects. Option C (CloudTrail) is incorrect because it records API activity for auditing, not encryption of data at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use SSL/TLS
Why it's wrong here
SSL/TLS encrypts data only while it is in transit between a client and the S3 service, creating a secure channel over the network. It does not alter the stored object or encrypt the object bytes at rest on S3's storage infrastructure. Therefore, using SSL/TLS alone cannot enforce encryption of data at rest, which is what SSE-KMS and SSE-C are designed to do.
- ✗
Use IAM policies
Why it's wrong here
IAM policies are authorization documents that determine which principals can perform which S3 actions, and they can include conditions such as requiring HTTPS or a specific encryption header. However, IAM policies themselves perform no cryptographic operations and do not encrypt a single byte of object data. They can deny unencrypted requests, but the actual encryption must be implemented by S3's server-side encryption features or by client-side encryption.
- ✗
Use AWS CloudTrail
Why it's wrong here
AWS CloudTrail is a governance, compliance, and auditing service that records API activity delivered to an S3 bucket but never acts on object payloads. While CloudTrail logs can show whether PutObject requests used encryption headers or which SSE-KMS key was invoked, log generation is reactive and does not cause data to be encrypted. CloudTrail is therefore an audit tool, not an encryption enforcement mechanism.
- ✓
Use SSE-KMS
Why this is correct
SSE-KMS (Server-Side Encryption with AWS KMS) instructs S3 to encrypt each object at rest using a customer managed KMS key, AWS managed KMS key, or AWS owned key. S3 calls KMS to generate a plaintext data key and an encrypted copy of that key, using envelope encryption to protect the object while maintaining the ability to rotate the KMS key independently. This gives you separation of duties, centralized key management, and auditability, making it a valid way to enforce at-rest encryption.
- ✓
Use SSE-C
Why this is correct
SSE-C (Server-Side Encryption with Customer-Provided Keys) lets you supply your own encryption key in the headers of each S3 request, which S3 uses to encrypt data at rest and to decrypt it when read. S3 performs a cryptographic hash of the key as a checksum but does not store the key itself, so you are fully responsible for managing, rotating, and protecting that key. This is a valid at-rest encryption method when you need to control your own keys and avoid KMS dependency.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.