Courseiva
Security →hardMultiple Choice

CV0-004 Security Practice Question

A cloud security engineer is responsible for an AWS environment that stores regulated data in Amazon S3 buckets. An audit finding states that data at rest in S3 is not encrypted with a customer-managed key, and the organization must retain control over key rotation and access policies. The engineer must implement encryption that satisfies the audit while minimizing changes to existing applications. Which approach should the engineer take?

⚠ Common exam trap

The trap here is equating any S3 encryption with compliance, when the audit specifically demands customer-managed keys and control over rotation, which only SSE-KMS with a customer-managed key provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure SSE-KMS with a customer-managed AWS KMS key and set the bucket default encryption to use that key.

SSE-KMS with a customer-managed key gives the organization control over key policies, rotation, and usage auditing while allowing S3 to handle encryption transparently. Setting it as the bucket default means applications do not need modification to encrypt new objects. Other options either leave key control with AWS or require significant application changes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable SSE-C by providing encryption keys in each S3 API request.

    Why it's wrong here

    SSE-C requires the caller to supply the encryption key on every PUT and GET request, which means application changes and careful key management outside AWS. It does not provide KMS-based rotation or policy control, and losing the key makes data unrecoverable. This does not align with minimizing changes or the audit's key-management expectations.

  • ✗

    Enable S3 default encryption using SSE-S3 (AES-256) on all buckets.

    Why it's wrong here

    SSE-S3 uses keys fully managed by AWS, so the organization does not control rotation or key access policies. While it encrypts data at rest, it does not meet the audit requirement for customer-managed keys. Applications would continue to work, but the control objective around key ownership would remain unsatisfied.

  • ✗

    Implement client-side encryption in each application before uploading objects to S3.

    Why it's wrong here

    Client-side encryption gives the organization full control over keys, but it requires modifying every application that reads or writes objects. The scenario asks to minimize application changes, and managing client-side keys adds significant operational overhead. It is a valid pattern but does not meet the stated constraint efficiently.

  • ✓

    Configure SSE-KMS with a customer-managed AWS KMS key and set the bucket default encryption to use that key.

    Why this is correct

    SSE-KMS with a customer-managed key lets the organization define key policies, control rotation, and audit key usage via CloudTrail. Setting it as the bucket default ensures new objects are encrypted automatically without application changes. This satisfies the audit requirement for customer-managed keys while minimizing disruption.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.