AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard

A company stores objects in Amazon S3 and wants encryption at rest where AWS fully manages the encryption keys with no additional configuration, versus another option where the company can control key policies, view usage in CloudTrail, and rotate keys, while paying a per-request and per-key fee. Which pair of options is being compared?

  1. ATLS encryption and VPC endpoint encryption
  2. BS3 Object Lock and S3 Versioning
  3. CSSE-C and client-side encryption
  4. DSSE-S3 and SSE-KMS
Show answer & explanation

Correct answer: D. SSE-S3 and SSE-KMS

SSE-S3 uses AWS-managed keys with no extra cost or configuration, while SSE-KMS uses AWS KMS customer managed keys, giving control over key policies, auditability via CloudTrail, and rotation, but incurs KMS API request charges.

Why the other options are wrong

  • A. TLS and VPC endpoints concern data in transit and network paths, not at-rest encryption options
  • B. Object Lock and Versioning relate to data protection, not encryption key management
  • C. SSE-C requires the customer to supply and manage keys themselves, not AWS-managed simplicity

SSE-S3 vs SSE-KMS

Two S3 server-side encryption options: SSE-S3 uses AWS-managed keys with no extra cost, while SSE-KMS uses customer managed KMS keys offering auditability, key policies, and rotation at additional cost.

  • SSE-S3: AES-256, keys fully managed by AWS, no CloudTrail key usage logging
  • SSE-KMS: keys are customer managed in KMS, usage logged in CloudTrail, incurs per-request fees
  • Choose SSE-KMS when you need granular access control or audit trails on key usage

Memory trick: S3 hides the key itself; KMS hands you the keyring to control.

More Security and Compliance questions