SCS-C02 exam dumps

SCS-C02 practice question 191 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 191

Single answer

An organization is using Amazon S3 to store sensitive customer data. To comply with regulatory requirements, the organization must ensure that data is encrypted at rest and that access to the encryption keys is tightly controlled. Which solution should the organization implement to meet these requirements?

  1. A

    Use Amazon S3 server-side encryption with Amazon S3-managed keys (SSE-S3).

  2. B

    Use Amazon S3 server-side encryption with AWS Key Management Service (AWS KMS) keys (SSE-KMS).

  3. C

    Use Amazon S3 client-side encryption with keys stored in an on-premises key management system.

  4. D

    Use Amazon S3 server-side encryption with customer-provided keys (SSE-C).

Show answer and explanation

Correct answer: B

Explanation

To meet regulatory requirements for encrypting data at rest and tightly controlling encryption key access, the best solution is Amazon S3 server-side encryption with AWS Key Management Service (AWS KMS) keys (SSE-KMS). This ensures that the data is encrypted while also allowing the organization to define granular access controls for the encryption keys using AWS KMS. Other options either do not provide sufficient control over encryption keys or introduce operational complexities.

  • A. Incorrect.

    Amazon S3 server-side encryption with S3-managed keys (SSE-S3) encrypts data at rest, but AWS manages the encryption keys, which does not offer granular control over key access as required by the scenario.

  • B. Correct.

    Amazon S3 server-side encryption with AWS KMS keys (SSE-KMS) encrypts data at rest and allows the organization to control access to encryption keys through IAM policies and AWS KMS key policies, meeting both encryption and key control requirements.

  • C. Incorrect.

    Amazon S3 client-side encryption with on-premises key storage provides encryption at rest, but managing keys on-premises increases complexity and does not leverage AWS's secure and scalable KMS solution.

  • D. Incorrect.

    Amazon S3 server-side encryption with customer-provided keys (SSE-C) requires the organization to supply keys for every operation, which can be operationally burdensome and does not offer the same robust controls as AWS KMS.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam