Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 42 pages
Exam (elaborations)

AWS CLF-C02 Encryption Exam Questions 2026–2027 | AWS KMS, Cryptographic Keys & Cloud Data Security Practice Test

Document preview thumbnail
Preview 4 out of 42 pages

Prepare for the AWS Certified Cloud Practitioner CLF-C02 2026–2027 exam with focused encryption and data-security practice. This resource covers AWS Key Management Service (KMS), cryptographic keys, encryption at rest, encryption in transit, key management concepts, data protection, and AWS security fundamentals. Realistic exam-style questions with answers and detailed explanations help reinforce how encryption protects AWS data and how KMS supports secure key management. Ideal for Cloud Practitioner candidates, students, IT professionals, cybersecurity learners, and AWS certification candidates seeking targeted security-domain revision and exam preparation.

Content preview

AWS CLF-C02 Encryption Exam
Questions 2026–2027 | KMS,
Cryptographic Keys & Cloud Data
Security Certification Prep


1. A company needs to encrypt data stored in Amazon S3 while retaining
control over the encryption keys. Which AWS service should it primarily
use?

A. AWS Secrets Manager
B. AWS Key Management Service (AWS KMS)
C. AWS Certificate Manager
D. Amazon GuardDuty

Answer: AWS Key Management Service (AWS KMS)

Rationale: AWS KMS provides managed cryptographic keys and integrates with
services such as Amazon S3, EBS, RDS, and many other AWS services for
encryption and decryption operations.

, 2. Which AWS KMS key type is designed to provide customers with the
greatest control over the underlying key material?

A. AWS owned key
B. AWS managed key
C. Customer managed key
D. Temporary session key

Answer: Customer managed key

Rationale: Customer managed KMS keys are created, managed, and controlled
by the customer, including policies, grants, rotation configuration, and deletion
scheduling.



3. A company wants AWS to manage the encryption key with minimal
administrative effort when using an AWS service. Which key category is
most appropriate?

A. Customer managed key
B. AWS managed key
C. External key stored in an HSM
D. Asymmetric customer key

Answer: AWS managed key

Rationale: AWS managed keys are created and managed by AWS for supported
AWS services, reducing the customer's key-management responsibilities.



4. Which statement best describes envelope encryption?

A. Encrypting the same plaintext multiple times with different passwords
B. Encrypting data with a data key and encrypting that data key with another key
C. Encrypting only metadata associated with a file
D. Encrypting a KMS key with a TLS certificate

,Answer: Encrypting data with a data key and encrypting that data key with
another key

Rationale: Envelope encryption uses a data key to encrypt the actual data and a
KMS key to protect the data key, improving scalability for large datasets.



5. Which AWS service is primarily responsible for creating and controlling
managed cryptographic keys?

A. AWS KMS
B. AWS IAM
C. Amazon Inspector
D. AWS CloudTrail

Answer: AWS KMS

Rationale: AWS KMS is the AWS managed service specifically designed for
creating, controlling, and using cryptographic keys.



6. A developer needs to encrypt a large file before storing it in Amazon S3.
Why is envelope encryption advantageous?

A. It eliminates the need for encryption
B. It allows the entire file to be encrypted directly by the KMS key
C. It allows efficient data encryption using a data key while KMS protects the data
key
D. It requires no key management

Answer: It allows efficient data encryption using a data key while KMS protects
the data key

Rationale: KMS operations are intended primarily for protecting cryptographic
keys and performing cryptographic operations, while data keys can efficiently
encrypt large amounts of data locally.

, 7. Which AWS KMS operation can generate a data key for client-side
encryption?

A. GenerateDataKey
B. EncryptBucket
C. CreateSessionKey
D. GenerateS3Key

Answer: GenerateDataKey

Rationale: GenerateDataKey generates a plaintext data key and an encrypted
version of that data key protected by the specified KMS key.



8. A company wants to prevent unauthorized IAM principals from using a KMS
key. Which mechanism directly controls access to the KMS key?

A. KMS key policy
B. Amazon Route 53 record
C. Security group
D. Network ACL

Answer: KMS key policy

Rationale: A KMS key policy is the primary resource-based policy mechanism for
controlling access to a KMS key. IAM policies can also participate when
permitted by the key policy.



9. What is the primary purpose of a KMS key policy?

A. Configure DNS resolution
B. Define permissions for using and managing a KMS key

Document information

Uploaded on
September 1, 2026
Number of pages
42
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
mml1030
2.6
(5)
Sold
8
Followers
0
Items
1207
Last sold
5 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions