SCS-C03 · D5 · 18%

Data Protection

Protect data in transit, at rest, and in use through ownership-aware encryption, key lifecycle decisions, secret handling, discovery, masking, and evidence.

Provider facts checked 2026-08-03

Objective coverage

Objective 5.1 · high

Protect data in transit

Select and troubleshoot TLS, certificate, private-path, service-to-service, and inter-resource encryption controls.

Lesson
d5-lesson
Practice pool
d5-questions
Application
scs-l06
Objective 5.2 · high

Protect data at rest

Choose encryption ownership, key material, rotation, grants, multi-Region strategy, access evidence, and recovery behavior.

Lesson
d5-lesson
Practice pool
d5-questions
Application
scs-l06
Objective 5.3 · high

Protect confidential data, credentials, secrets, and key material

Discover, classify, mask, store, rotate, scope, and monitor access to confidential material throughout its lifecycle.

Lesson
d5-lesson
Practice pool
d5-questions
Application
scs-l06, scs-l07

title: "Data Protection" summary: "Decision-focused guidance for AWS data classification, encryption, key ownership, lifecycle, and recovery controls."

Begin with ownership and data state

Classify the information, identify owners and custodians, and trace collection, use, sharing, retention, recovery, and deletion. Then choose protection for data in transit, at rest, and where relevant in use. Encryption does not fix overbroad access, poor retention, or exposed plaintext in logs.

In transit

Map every hop: client to edge, edge to origin, service to service, node to node, hybrid path, and administrative channel. Choose certificates, trust roots, TLS policies, mutual authentication, private paths, and inter-resource encryption from threat and compliance requirements. Validate the negotiated path and failure behavior rather than relying on a configuration label.

At rest and key lifecycle

Distinguish AWS-owned, AWS-managed, and customer-managed keys. Customer-managed KMS keys add policy, grant, rotation, usage-evidence, deletion, and cross-account responsibilities. Imported material shifts lifecycle and recoverability duties. Multi-Region keys are for designs that need compatible key material across Regions; they do not replicate encrypted data or remove application failover work.

Secrets and confidential material

Use managed secret storage, workload identities, rotation, scoped access, version stages, failure alarms, and audit evidence. Discover and mask sensitive data where appropriate. Never emit secrets, raw credentials, or protected prompts into logs.

Self-check

For one cross-account, multi-Region data flow, defend the key owner, policies, certificate path, rotation behavior, recovery plan, and evidence that proves authorized and denied use.