Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud security engineer is configuring an Amazon S3 bucket that must store sensitive financial data. The requirement is that all data must be encrypted at rest with keys that the organization controls and can rotate, and that access to the keys must be auditable and separable from the data access permissions. Which S3 encryption option BEST meets these requirements?

⚠ Common exam trap

The trap here is choosing SSE-C or client-side encryption because they seem to offer more control, while overlooking that SSE-KMS with a customer managed key already provides control, rotation, and integrated auditability without the operational burden.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSE-KMS with a customer managed key in AWS KMS, with a key policy that grants decrypt permissions only to specific roles and enables automatic key rotation.

The requirement calls for customer-controlled keys, rotation, and auditable, separable key access. SSE-KMS with a customer managed key in AWS KMS satisfies all three: the organization creates and controls the key, can enable automatic rotation, and uses key policies and IAM to separate key access from S3 data access. CloudTrail logs every KMS operation, providing the needed audit trail. Other options either use AWS-managed keys or shift key management outside AWS, failing at least one requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSE-C where the customer provides the encryption key with each request, and the key is stored in AWS Secrets Manager for automatic retrieval.

    Why it's wrong here

    SSE-C requires the customer to provide the key on every request, and AWS does not store the key. Storing it in Secrets Manager introduces operational complexity and does not provide built-in key rotation or KMS-level auditability. It also does not separate key access permissions from data access in the way KMS key policies do.

  • ✓

    SSE-KMS with a customer managed key in AWS KMS, with a key policy that grants decrypt permissions only to specific roles and enables automatic key rotation.

    Why this is correct

    SSE-KMS with a customer managed key gives the organization control over the key, supports automatic rotation, and allows a key policy that is separate from S3 bucket policies. AWS CloudTrail logs all KMS key usage, providing auditability, and access to keys can be granted independently of access to the S3 data.

  • ✗

    SSE-S3 with default bucket encryption enabled and S3 Block Public Access turned on.

    Why it's wrong here

    SSE-S3 uses AWS-managed keys that the customer does not control or rotate directly, and key usage is not separately auditable via customer-controlled policies. While it encrypts data at rest, it fails the requirements for customer-controlled keys and separable, auditable key access permissions.

  • ✗

    Client-side encryption using the AWS Encryption SDK with a master key stored in an on-premises HSM, and uploading the encrypted objects to S3.

    Why it's wrong here

    Client-side encryption with an on-premises HSM gives the organization full control, but it complicates key rotation and auditability because key usage logs reside on-premises and are not integrated with AWS CloudTrail. It also does not leverage S3 server-side encryption features, and the requirement for separable, auditable key access is harder to achieve operationally.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.