SOA-C02 Security and Compliance Practice Question
A SysOps administrator is tasked with encrypting data at rest for an Amazon S3 bucket that stores sensitive customer information. The company requires that the encryption keys be managed by AWS and rotated automatically. Which encryption solution meets these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use server-side encryption with Amazon S3-managed keys (SSE-S3).
SSE-S3 uses Amazon S3-managed keys that are automatically rotated by AWS, meeting the requirement for AWS-managed and automatic rotation. Option A is wrong because client-side encryption is not managed by AWS and does not use server-side encryption. Option B is wrong because SSE-C requires the customer to provide their own encryption keys, which are not automatically rotated. Option D is wrong because SSE-KMS uses AWS KMS keys that are customer-managed unless automatic rotation is specifically enabled, and the question requires automatic rotation without additional configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use client-side encryption with AWS KMS.
Why it's wrong here
Client-side encryption with AWS KMS is performed before the object ever reaches Amazon S3, so the encryption and decryption process is your responsibility, not AWS's. While AWS KMS can generate data keys for envelope encryption, your application must implement the cryptographic operations, manage SDK integration, and handle key versioning. Because the task is to encrypt data at rest in S3 with minimal operational burden, this approach adds complexity and does not use S3's native server-side encryption features.
- ✗
Use server-side encryption with customer-provided keys (SSE-C).
Why it's wrong here
Server-side encryption with customer-provided keys (SSE-C) requires you to supply an encryption key in each request, and S3 uses that key to encrypt the object at rest but does not store the key. You must manage and rotate the keys yourself, and you lose out on automatic key rotation and AWS-managed access controls. Since the requirement asks for encrypting data at rest with AWS managing encryption keys, SSE-C is not the appropriate choice because the customer, not AWS, manages the key lifecycle.
- ✓
Use server-side encryption with Amazon S3-managed keys (SSE-S3).
Why this is correct
Server-side encryption with Amazon S3-managed keys (SSE-S3) is the simplest way to encrypt data at rest in S3: S3 automatically encrypts each object with a unique key that is itself wrapped by a root key, all managed by AWS. These keys are automatically rotated on a regular basis, so you have no key material to manage or rotate, and there is no additional cost. This directly meets the requirement of encrypting data at rest with AWS managing the keys, making it the correct answer.
- ✗
Use server-side encryption with AWS KMS (SSE-KMS).
Why it's wrong here
Server-side encryption with AWS KMS (SSE-KMS) encrypts S3 objects using customer-managed KMS keys, which gives you separate permissions and audit trails, but those KMS keys are not automatically rotated unless you explicitly enable automatic key rotation. Even when rotation is enabled, the key version changes are managed by KMS, but you may incur per-request charges and need to handle key policies and grants. Because the requirement does not ask for these extra controls, SSE-S3 provides the same core encryption with less administrative overhead, so SSE-KMS is not the best answer.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.