SCS-C02 exam dumps

SCS-C02 practice question 363 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 363

Single answer

A company is storing sensitive customer data in Amazon S3 and needs to ensure the data is encrypted both in transit and at rest. Additionally, the company requires full control over the encryption keys and must ensure that only authorized users in their organization can decrypt the data. Which encryption technique should the company use?

  1. A

    Server-side encryption with Amazon S3-managed keys (SSE-S3)

  2. B

    Server-side encryption with AWS Key Management Service (KMS) keys (SSE-KMS)

  3. C

    Client-side encryption using a custom key management solution

  4. D

    Server-side encryption with customer-provided keys (SSE-C)

Show answer and explanation

Correct answer: C

Explanation

In this scenario, the company needs encryption both in transit and at rest, with full control over the encryption keys. Client-side encryption is the best choice as it encrypts the data before it is sent to Amazon S3, ensuring protection in transit. Additionally, because the company manages the encryption process and keys, they retain full control over key access and use.

  • A. Incorrect.

    SSE-S3 uses keys managed by Amazon S3, which does not provide the company full control over the encryption keys. This option is not suitable for the company’s requirement of controlling the keys.

  • B. Incorrect.

    SSE-KMS uses AWS KMS for key management, which allows some control over key policies but does not provide complete control over the keys since AWS still manages certain aspects of KMS. This does not fully meet the requirement.

  • C. Correct.

    Client-side encryption ensures the company encrypts the data before sending it to S3, and the encryption keys are fully managed by the company. This gives the company full control over the keys and satisfies the requirement for ensuring that only authorized users in their organization can decrypt the data.

  • D. Incorrect.

    SSE-C requires the company to provide encryption keys for each S3 request, but the actual encryption occurs on the server-side. While this allows key control, it does not directly address the need to encrypt the data before it is transmitted to the server, leaving the data potentially vulnerable in transit.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam