CV0-004 Security Practice Question
A cloud security engineer is responsible for an AWS environment that stores regulated data in Amazon S3 buckets. An audit finding states that data at rest in S3 is not encrypted with a customer-managed key, and the organization must retain control over key rotation and access policies. The engineer must implement encryption that satisfies the audit while minimizing changes to existing applications. Which approach should the engineer take?
⚠ Common exam trap
The trap here is equating any S3 encryption with compliance, when the audit specifically demands customer-managed keys and control over rotation, which only SSE-KMS with a customer-managed key provides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure SSE-KMS with a customer-managed AWS KMS key and set the bucket default encryption to use that key.
SSE-KMS with a customer-managed key gives the organization control over key policies, rotation, and usage auditing while allowing S3 to handle encryption transparently. Setting it as the bucket default means applications do not need modification to encrypt new objects. Other options either leave key control with AWS or require significant application changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable SSE-C by providing encryption keys in each S3 API request.
Why it's wrong here
SSE-C requires the caller to supply the encryption key on every PUT and GET request, which means application changes and careful key management outside AWS. It does not provide KMS-based rotation or policy control, and losing the key makes data unrecoverable. This does not align with minimizing changes or the audit's key-management expectations.
- ✗
Enable S3 default encryption using SSE-S3 (AES-256) on all buckets.
Why it's wrong here
SSE-S3 uses keys fully managed by AWS, so the organization does not control rotation or key access policies. While it encrypts data at rest, it does not meet the audit requirement for customer-managed keys. Applications would continue to work, but the control objective around key ownership would remain unsatisfied.
- ✗
Implement client-side encryption in each application before uploading objects to S3.
Why it's wrong here
Client-side encryption gives the organization full control over keys, but it requires modifying every application that reads or writes objects. The scenario asks to minimize application changes, and managing client-side keys adds significant operational overhead. It is a valid pattern but does not meet the stated constraint efficiently.
- ✓
Configure SSE-KMS with a customer-managed AWS KMS key and set the bucket default encryption to use that key.
Why this is correct
SSE-KMS with a customer-managed key lets the organization define key policies, control rotation, and audit key usage via CloudTrail. Setting it as the bucket default ensures new objects are encrypted automatically without application changes. This satisfies the audit requirement for customer-managed keys while minimizing disruption.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.