CloudGuild · Blog · Cheat sheets · Lessons · Certifications

Walkthrough: AWS Certified Security - Specialty (SCS-C02) Encryption Keys Question

Explore a key question from the AWS Certified Security - Specialty exam and learn how to choose the right AWS service for managing encryption keys.

Choosing the right AWS service for encryption key management can trip up candidates. This question tests your understanding of AWS services and their specific functions.

The question

A security engineer is tasked with ensuring that all personal identifiable information (PII) stored in an Amazon RDS database is encrypted. Which AWS service should the engineer use to manage the encryption keys for this data?

Think before you scroll

Consider the specific functionalities of each service. Focus on which service is designed specifically for managing encryption keys and integrates well with RDS.

The answer

The correct option is B. AWS Key Management Service (KMS). KMS is built for managing encryption keys and is fully integrated with Amazon RDS, making it the most suitable choice for this scenario.

Why the other options lose

The concept behind it

The principle to grasp here is that AWS services are designed for specific purposes. When tasked with encryption key management, KMS is the go-to service due to its integration and specialized functionality. Understanding each service’s role helps in making the correct choice.

Exam trap to remember

Remember: when it comes to managing encryption keys specifically, KMS is king. Always consider the primary function of the service in question.

Take the free SCS-C02 mock exam

Take a free mock exam →