SOA-C02 Security and Compliance Practice Question
Which TWO services can be used to centrally manage cryptographic keys for AWS services? (Choose two.)
⚠ Common exam trap
SOA-C02 often tests the distinction between services that manage keys (KMS, CloudHSM) versus services that manage certificates (ACM) or secrets (Secrets Manager), catching candidates who conflate 'cryptographic material' with 'key management'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS CloudHSM
AWS CloudHSM (A) is correct because it provides dedicated, single-tenant hardware security modules in the AWS cloud where you can generate, store, and manage cryptographic keys, giving you full control over the key material for AWS services and custom applications. AWS Key Management Service (D) is correct because it is a managed service specifically designed to create, store, and centrally control cryptographic keys used to encrypt data across AWS services and applications, integrating natively with many AWS offerings. AWS Certificate Manager (B) is not a key management service; it provisions, manages, and deploys SSL/TLS certificates, though it can integrate with KMS for private CA keys. AWS Identity and Access Management (C) manages identities, permissions, and access policies, not cryptographic key material. AWS Secrets Manager (E) stores and rotates secrets such as database credentials and API keys, but it is not intended for centrally managing cryptographic keys for AWS services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS CloudHSM
Why this is correct
AWS CloudHSM is a hardware security module (HSM) service that provides dedicated, FIPS 140-2 Level 3 validated cryptographic appliances under your exclusive control. It enables centralized, secure key generation, storage, and cryptographic operations using industry-standard APIs (PKCS#11, JCE, Microsoft CNG) while keeping keys isolated in tamper-resistant hardware, making it one of the two services that directly manage cryptographic keys.
- ✗
AWS Certificate Manager (ACM)
Why it's wrong here
AWS Certificate Manager (ACM) is a service for provisioning, managing, and deploying SSL/TLS certificates, not for managing the underlying cryptographic keys themselves. While ACM does handle private keys for public certificates, these keys are managed by AWS internally and are not exposed to customers; ACM does not provide a customer-controlled key store or APIs for generic cryptographic operations, so it is not a service for centrally managing cryptographic keys.
- ✗
AWS Identity and Access Management (IAM)
Why it's wrong here
AWS Identity and Access Management (IAM) is an authorization and access-control service that defines users, groups, roles, and policies to control who can access AWS resources. IAM does not generate, store, or manage encryption keys; instead, it controls permissions to use services such as KMS or CloudHSM. Its role is to grant or deny access to key management APIs, not to act as a key management system itself.
- ✓
AWS Key Management Service (KMS)
Why this is correct
AWS Key Management Service (KMS) is a managed service that allows you to create, rotate, and control the lifecycle of symmetric and asymmetric encryption keys, commonly known as customer master keys (CMKs). KMS is integrated with many AWS services and uses FIPS 140-2 validated hardware to perform cryptographic operations, exposing a centralized API for key administration, auditing via CloudTrail, and granular access control through IAM policies, making it one of the two services specifically built for key management.
- ✗
AWS Secrets Manager
Why it's wrong here
AWS Secrets Manager is designed to securely store and rotate secrets such as database credentials, API keys, and other sensitive configuration values. Although it encrypts secrets with KMS keys, the service itself does not manage or expose the underlying cryptographic keys; its core function is secret lifecycle management, not key generation or cryptographic operations. Therefore, Secrets Manager is not considered a central cryptographic key management service.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.