Skip to content
BytePatterns

SCS-C03 · Domain 5: Data Protection · 18% of the exam

Task 5.2: Design and implement controls for data at rest

Protecting stored data: choosing KMS or CloudHSM and client-side or server-side encryption, guarding integrity with Object Lock, Vault Lock, versioning and signatures, automatic lifecycle and retention, and backups and copies that survive ransomware.

Study it

  • Encryption at rest: KMS, CloudHSM, client-side and server-side

    Partly covered by: KMS, Envelope Encryption & Private CA

  • Integrity: Object Lock, Glacier Vault Lock, versioning and signing

    Lesson coming

  • Retention and lifecycle: S3 Lifecycle, EFS lifecycle and backup policies

    Partly covered by: S3: Consistency, Classes, Lifecycle

  • Backups that survive ransomware: AWS Backup, Vault Lock and Data Lifecycle Manager

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

Trade records stored in S3 must be kept for seven years. During that time nobody, including the root user, may delete or overwrite them. The legal team must also be able to keep individual records beyond seven years, with no end date, while litigation is open. Which configuration meets these requirements?

  1. AObject Lock in governance mode with seven-year default retention, plus legal holds
  2. BS3 Versioning with MFA delete turned on by the root user
  3. CAmazon Glacier Vault Lock with a seven-year policy for the bucket
  4. DObject Lock in compliance mode with seven-year default retention, plus legal holds
Show the answer and why
  • AObject Lock in governance mode with seven-year default retention, plus legal holds

    Incorrect

    In governance mode, users with s3:BypassGovernanceRetention can remove the protection, so the records are not safe from everyone.

  • BS3 Versioning with MFA delete turned on by the root user

    Incorrect

    MFA delete adds a step for deleting versions, but a user with the MFA device and permissions can still delete them.

  • CAmazon Glacier Vault Lock with a seven-year policy for the bucket

    Incorrect

    Vault Lock policies apply to vaults in the standalone Amazon Glacier service, which no longer accepts new customers, not to objects in S3 buckets.

  • DObject Lock in compliance mode with seven-year default retention, plus legal holds

    Correct

    Compliance mode stops anyone, including the root user, from deleting or overwriting a version during retention; a legal hold has no expiry until removed.

Compliance mode makes retention unbreakable, and legal holds extend protection for as long as needed. Object Lock requires versioning on the bucket.

Question 2 · choose 1

A company must encrypt its EBS volumes and S3 objects through the normal AWS KMS integrations. Its regulator requires that the key material is generated and used only in single-tenant HSMs in a cluster that the company controls, and that the company can cut off all use of the keys at once by disconnecting. Which solution meets these requirements?

  1. ACustomer managed KMS keys in the standard AWS KMS key store
  2. BKMS keys in an AWS CloudHSM key store backed by the company's CloudHSM cluster
  3. CA CloudHSM cluster used directly by the applications for client-side encryption
  4. DCustomer managed KMS keys with imported key material
Show the answer and why
  • ACustomer managed KMS keys in the standard AWS KMS key store

    Incorrect

    These keys are protected by FIPS 140-3 Level 3 validated HSMs, but the HSMs are managed by AWS KMS, not a single-tenant cluster the company controls.

  • BKMS keys in an AWS CloudHSM key store backed by the company's CloudHSM cluster

    Correct

    The key material is generated and used in the company's own CloudHSM cluster, the keys work with integrated services, and disconnecting the key store stops their use.

  • CA CloudHSM cluster used directly by the applications for client-side encryption

    Incorrect

    Client-side encryption in the application bypasses the EBS and S3 integrations with AWS KMS that the company must use.

  • DCustomer managed KMS keys with imported key material

    Incorrect

    Imported material is stored and used in AWS KMS HSMs, and it cannot be imported into keys in a custom key store.

Standard KMS already meets FIPS 140-3 Level 3. The deciding words are "single-tenant cluster the company controls" plus "service integration", which point to a CloudHSM key store.

Question 3 · choose 2

After a ransomware incident at a peer company, a security team wants its AWS Backup recovery points protected so that even someone with administrator or root access to the workload account cannot delete them before their retention ends, and so that a copy can be restored from another account if the workload account is lost. Which actions meet these requirements? (Choose TWO.)

  1. ALock the backup vault with AWS Backup Vault Lock in governance mode
  2. BLock the backup vault with AWS Backup Vault Lock in compliance mode
  3. CTurn on continuous backup for point-in-time recovery of the resources
  4. DCreate AWS Backup Audit Manager frameworks that report on backup compliance
  5. ECopy recovery points to a vault in a separate backup account
Show the answer and why
  • ALock the backup vault with AWS Backup Vault Lock in governance mode

    Incorrect

    A governance mode lock can be removed by users with sufficient IAM permissions, so a compromised administrator could remove it.

  • BLock the backup vault with AWS Backup Vault Lock in compliance mode

    Correct

    After the grace time, a compliance mode lock cannot be changed or removed by any user, including the root user, or by AWS.

  • CTurn on continuous backup for point-in-time recovery of the resources

    Incorrect

    Continuous backup improves the recovery point, but it does not stop an administrator from deleting the backups.

  • DCreate AWS Backup Audit Manager frameworks that report on backup compliance

    Incorrect

    Backup Audit Manager reports whether backups meet controls. It does not prevent deletion.

  • ECopy recovery points to a vault in a separate backup account

    Correct

    Cross-account copies keep restorable backups outside the workload account, so losing that account does not lose the backups.

Immutability and isolation answer different threats: a compliance lock stops deletion, and a copy in another account survives the loss of the first. AWS also offers logically air-gapped vaults that combine both ideas.

Question 4 · choose 1

A company must share EBS snapshots of a database server with its disaster recovery account. The snapshots are encrypted with the default AWS managed key for EBS (aws/ebs). The share fails. What should the team do?

  1. ARe-encrypt copies with a customer managed key, share the key, then share the copies
  2. BEdit the key policy of the aws/ebs key to allow the DR account to use it
  3. CMake the snapshots public for a few minutes and copy them from the DR account
  4. DTurn off EBS encryption by default in the Region, then take and share new snapshots
Show the answer and why
  • ARe-encrypt copies with a customer managed key, share the key, then share the copies

    Correct

    Snapshots encrypted with the default AWS managed key cannot be shared. Re-encrypted copies under a customer managed key can be, together with the key.

  • BEdit the key policy of the aws/ebs key to allow the DR account to use it

    Incorrect

    Key policies of AWS managed keys cannot be changed, so this key cannot be shared.

  • CMake the snapshots public for a few minutes and copy them from the DR account

    Incorrect

    Only unencrypted snapshots can be shared publicly, and doing so would expose the data.

  • DTurn off EBS encryption by default in the Region, then take and share new snapshots

    Incorrect

    Unencrypted snapshots would break the encryption requirement and do not fix the existing snapshots.

Anything you want to share across accounts must be encrypted with a key you control. Use customer managed keys from the start for data that may need to be shared.

Question 5 · choose 1

A developer uploads objects to a new S3 bucket without asking for any encryption. How are the objects stored?

  1. AEncrypted with SSE-S3 by default
  2. BUnencrypted, until default encryption is set
  3. CEncrypted with the account's aws/s3 KMS key
  4. DEncrypted with a key the developer must provide
Show the answer and why
  • AEncrypted with SSE-S3 by default

    Correct

    Amazon S3 applies server-side encryption with S3 managed keys as the base level of encryption for every bucket.

  • BUnencrypted, until default encryption is set

    Incorrect

    S3 applies SSE-S3 to every bucket as the base level.

  • CEncrypted with the account's aws/s3 KMS key

    Incorrect

    SSE-KMS is used only when it is configured or requested.

  • DEncrypted with a key the developer must provide

    Incorrect

    The uploader does not have to supply any key; with no encryption request, S3 applies its base level of encryption on its own.

Choose SSE-KMS when you need control over the key and key-usage logs.

Question 6 · choose 1

A versioned bucket holds financial records. The company wants every permanent deletion of an object version, and every change to the versioning state, to require a second authentication factor. What should it configure, and who can turn it on?

  1. AMFA delete, turned on by any IAM administrator
  2. BMFA delete, turned on by the owner's root account
  3. CAn IAM policy condition requiring MFA for s3:PutObject
  4. DS3 Object Lock in governance mode with no retention
Show the answer and why
  • AMFA delete, turned on by any IAM administrator

    Incorrect

    Only the bucket owner's root account can turn on MFA delete.

  • BMFA delete, turned on by the owner's root account

    Correct

    MFA delete requires two forms of authentication for these actions, and only the bucket owner (root account) can enable it.

  • CAn IAM policy condition requiring MFA for s3:PutObject

    Incorrect

    Uploads are not the concern; deletions of versions are.

  • DS3 Object Lock in governance mode with no retention

    Incorrect

    Governance mode needs a retention period and is not MFA delete.

For retention that no one can shorten, consider Object Lock in compliance mode instead.

Question 7 · choose 1

Legal asks that certain S3 objects be protected from deletion for an investigation of unknown length. When it ends, legal will release them. Which Object Lock feature fits?

  1. AA legal hold on the object versions
  2. BA retention period in compliance mode for ten years
  3. CA lifecycle rule that expires the objects later
  4. DA bucket policy that denies GetObject
Show the answer and why
  • AA legal hold on the object versions

    Correct

    A legal hold gives the same protection as a retention period but has no expiration date; it stays until removed.

  • BA retention period in compliance mode for ten years

    Incorrect

    A fixed period cannot be shortened in compliance mode and does not match an unknown end date.

  • CA lifecycle rule that expires the objects later

    Incorrect

    Lifecycle rules delete or transition objects; they do not protect them.

  • DA bucket policy that denies GetObject

    Incorrect

    Denying reads does not protect against deletion.

An object version can have both a retention period and a legal hold.

Question 8 · choose 1

An encrypted RDS DB instance in us-east-1 needs an encrypted read replica in eu-west-1. Which KMS key does the team choose for the replica?

  1. AThe same KMS key ARN as the source in us-east-1
  2. BNo key, because cross-Region replicas are never encrypted
  3. CA KMS key in the destination Region, eu-west-1
  4. DAny key, as long as it is an AWS owned key
Show the answer and why
  • AThe same KMS key ARN as the source in us-east-1

    Incorrect

    KMS keys are Regional; the replica uses a key in its own Region.

  • BNo key, because cross-Region replicas are never encrypted

    Incorrect

    Encrypted cross-Region replicas are supported for encrypted sources.

  • CA KMS key in the destination Region, eu-west-1

    Correct

    For an encrypted replica in another Region, you choose the identifier of a KMS key in the destination Region.

  • DAny key, as long as it is an AWS owned key

    Incorrect

    The replica is encrypted with a KMS key you choose in the destination Region.

Multi-Region keys can simplify this, but a separate key per Region also works.

Question 9 · choose 1

Which statement about RDS encryption at rest is correct for a new DB instance with encryption turned on?

  1. AOnly the data files are encrypted, not its backups or logs
  2. BApplications must call KMS to read each row
  3. CSnapshots of the instance are stored unencrypted
  4. DIts logs, backups, replicas and snapshots are encrypted
Show the answer and why
  • AOnly the data files are encrypted, not its backups or logs

    Incorrect

    Logs, automated backups, read replicas and snapshots are encrypted too.

  • BApplications must call KMS to read each row

    Incorrect

    Encryption is transparent; client applications need no changes.

  • CSnapshots of the instance are stored unencrypted

    Incorrect

    Snapshots of an encrypted instance are encrypted.

  • DIts logs, backups, replicas and snapshots are encrypted

    Correct

    For an encrypted DB instance, logs, backups, read replicas and snapshots are encrypted as well.

Encryption is chosen at creation; an existing unencrypted instance needs an encrypted snapshot copy and a restore.

Practise domain 5 →Practise all domains →