Amazon
SCS-C02 · Question #265
A company wants to encrypt data locally while meeting regulatory requirements related to key exhaustion. The encryption key can be no more than 10 days old or encrypt more than 2" 16 objects Any…
The correct answer is A. Use the AWS Encryption SDK and set the maximum age to 10 days and the minimum number of. See the full explanation below for the reasoning.
Submitted by jian89· Mar 6, 2026Data Protection
Question
A company wants to encrypt data locally while meeting regulatory requirements related to key exhaustion. The encryption key can be no more than 10 days old or encrypt more than 2" 16 objects Any encryption key must be generated on a FlPS-validated hardware security module (HSM). The company is cost- conscious, as plans to upload an average of 100 objects to Amazon S3 each second for sustained operations across 5 data producers When approach MOST efficiently meets the company's needs?
Options
- AUse the AWS Encryption SDK and set the maximum age to 10 days and the minimum number of
- BUse AWS Key Management Service (AWS KMS) to generate an AWS managed CMK.
- CUse AWS CloudHSM to generate the master key and data keys.
- DUse server-side encryption with Amazon S3 managed encryption keys (SSE-S3) and set the
How the community answered
(63 responses)- A57% (36)
- B11% (7)
- C6% (4)
- D25% (16)
Topics
#Client-Side Encryption#Key Management#AWS Encryption SDK#Regulatory Compliance
Community Discussion
No community discussion yet for this question.