Instiq
Chapter 5 · Data Protection·v2.0.0·Updated 6/5/2026·~8 min

What's changed: Deepened SCS-C02 Chapter 5 (added comparison tables, scenarios, FAQs, exam traps, deep-dive paragraphs to each section; localized figures to Japanese)

5.4In-scope services for data protection

Key points

A roundup of in-scope SCS-C03 services for data protection.

5.4.1In-scope services for data protection

For data protection, beyond KMS/CloudHSM/Secrets Manager/Macie, know: AWS Private Certificate Authority (a private CA for internal services), Amazon Data Lifecycle Manager (policy-based automation of EBS snapshot/AMI creation/retention/deletion), Amazon S3 (subject to bucket policies/encryption), Amazon Elastic File System and high-performance Amazon FSx for Lustre (shared files), and AWS DataSync (transfer data with encryption and integrity validation).

Diagram grouping certificates (AWS Private Certificate Authority), backup lifecycle (Amazon Data Lifecycle Manager), and storage/transfer (S3/EFS/FSx for Lustre/DataSync).
Data protection services

5.4.2Section summary

  • Certs/backup: Private Certificate Authority / Data Lifecycle Manager (snapshot lifecycle)
  • Storage/transfer: S3 / EFS / FSx for Lustre / DataSync (encrypted transfer)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. Which certificate authority issues/manages private certificates for internal services’ mutual TLS (mTLS)?

Q2. Which automates creation/retention/deletion of EBS snapshots and AMIs via policy for lifecycle management?

Check your understandingPractice questions for Chapter 5: Data Protection

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.