Courseiva
Data Protection →mediumMultiple Select

SCS-C02 Data Protection Practice Question

Which TWO of the following are valid ways to enforce encryption at rest for data in Amazon S3? (Choose TWO.)

⚠ Common exam trap

SCS-C02 often tests the difference between encryption in transit and at rest; candidates may select SSL/TLS or IAM policies, but those do not enforce encryption at rest.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use SSE-KMS

SSE-KMS (option D) is correct because it enforces server-side encryption at rest by having Amazon S3 encrypt objects with keys managed in AWS KMS, providing envelope encryption and auditability via CloudTrail. SSE-C (option E) is also correct because it enforces server-side encryption at rest using a customer-provided encryption key that S3 applies to the object, so data is stored encrypted on disk. Option A (SSL/TLS) is incorrect because it only protects data in transit between the client and S3, not data at rest. Option B (IAM policies) is incorrect because IAM controls authorization and permissions, not the encryption of stored objects. Option C (CloudTrail) is incorrect because it records API activity for auditing, not encryption of data at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use SSL/TLS

    Why it's wrong here

    SSL/TLS encrypts data only while it is in transit between a client and the S3 service, creating a secure channel over the network. It does not alter the stored object or encrypt the object bytes at rest on S3's storage infrastructure. Therefore, using SSL/TLS alone cannot enforce encryption of data at rest, which is what SSE-KMS and SSE-C are designed to do.

  • ✗

    Use IAM policies

    Why it's wrong here

    IAM policies are authorization documents that determine which principals can perform which S3 actions, and they can include conditions such as requiring HTTPS or a specific encryption header. However, IAM policies themselves perform no cryptographic operations and do not encrypt a single byte of object data. They can deny unencrypted requests, but the actual encryption must be implemented by S3's server-side encryption features or by client-side encryption.

  • ✗

    Use AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail is a governance, compliance, and auditing service that records API activity delivered to an S3 bucket but never acts on object payloads. While CloudTrail logs can show whether PutObject requests used encryption headers or which SSE-KMS key was invoked, log generation is reactive and does not cause data to be encrypted. CloudTrail is therefore an audit tool, not an encryption enforcement mechanism.

  • ✓

    Use SSE-KMS

    Why this is correct

    SSE-KMS (Server-Side Encryption with AWS KMS) instructs S3 to encrypt each object at rest using a customer managed KMS key, AWS managed KMS key, or AWS owned key. S3 calls KMS to generate a plaintext data key and an encrypted copy of that key, using envelope encryption to protect the object while maintaining the ability to rotate the KMS key independently. This gives you separation of duties, centralized key management, and auditability, making it a valid way to enforce at-rest encryption.

  • ✓

    Use SSE-C

    Why this is correct

    SSE-C (Server-Side Encryption with Customer-Provided Keys) lets you supply your own encryption key in the headers of each S3 request, which S3 uses to encrypt data at rest and to decrypt it when read. S3 performs a cryptographic hash of the key as a checksum but does not store the key itself, so you are fully responsible for managing, rotating, and protecting that key. This is a valid at-rest encryption method when you need to control your own keys and avoid KMS dependency.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.