AWS Certified Developer Associate DVA-C02 Practice Question
A financial services company needs a secure way to manage the lifecycle of the encryption keys that protect its data in AWS. The security team wants the key material to refresh automatically on a predictable schedule without requiring any application changes. Which action will meet this requirement?
Enable automatic rotation for a customer-managed KMS key
Develop a custom script that re-creates the encryption key and updates all references each year
Create a schedule to run the RotateKeyOnDemand API for the AWS-managed KMS key every quarter
Add a condition to the key policy that sets the rotation frequency to 90 days
AWS Key Management Service (AWS KMS) lets you turn on automatic rotation for a customer-managed symmetric encryption key. When automatic rotation is enabled, AWS KMS generates new cryptographic material for the key at the rotation interval (365 days by default, or a custom period that you specify between 90 and 2,560 days). Because AWS KMS stores previous key-material versions and automatically selects the right version during decrypt operations, no code or configuration changes are needed in the applications that use the key.
AWS-managed KMS keys already rotate automatically every year and do not allow you to change the schedule or initiate rotation manually. Writing custom scripts or editing the key policy does not provide automatic rotation and adds operational overhead without changing AWS KMS rotation behavior.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Customer Master Key (CMK) in AWS?
Open an interactive chat with Bash
What does it mean to enable automatic rotation for a CMK?
Open an interactive chat with Bash
Why is automatic key rotation considered a best practice?
Open an interactive chat with Bash
AWS Certified Developer Associate DVA-C02
Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access