SCS-C02 exam dumps

SCS-C02 practice question 355 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 355

Single answer

You are designing a storage solution for sensitive financial data in Amazon S3. The data must be encrypted at rest to ensure its confidentiality and integrity. Additionally, you must maintain control over the encryption keys and meet compliance requirements for auditing access. Which solution will best meet these requirements?

  1. A

    Use Amazon S3 server-side encryption with AWS Key Management Service (SSE-KMS) and default AWS-managed keys.

  2. B

    Use Amazon S3 server-side encryption with customer-provided keys (SSE-C).

  3. C

    Use Amazon S3 server-side encryption with AWS Key Management Service (SSE-KMS) and customer-managed keys.

  4. D

    Use client-side encryption and store the encryption keys in AWS Secrets Manager.

Show answer and explanation

Correct answer: C

Explanation

SSE-KMS with customer-managed keys is the ideal solution for encrypting sensitive data in S3 when you need to maintain control over encryption keys and meet compliance requirements. It integrates with AWS Key Management Service for key management, auditing, and compliance while ensuring the data is encrypted at rest.

  • A. Incorrect.

    SSE-KMS with default AWS-managed keys provides encryption but does not allow you to maintain full control over the encryption keys. AWS retains control over the keys, which may not meet compliance requirements.

  • B. Incorrect.

    SSE-C allows you to provide your own keys, but it does not integrate with AWS Key Management Service for key management and auditing. This makes compliance and operational management more challenging.

  • C. Correct.

    SSE-KMS with customer-managed keys enables you to maintain full control over the encryption keys. It integrates with AWS Key Management Service, providing detailed key management, rotation, and auditing capabilities to meet compliance requirements.

  • D. Incorrect.

    Client-side encryption requires you to manage encryption keys yourself, which can increase operational complexity. While AWS Secrets Manager can securely store keys, this approach may not fully leverage AWS's integrated encryption and auditing capabilities.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam