What feature should be enabled to automatically change the backend cryptographic material of an encryption key used with AWS services to minimize the potential impact of a compromised key?
Setting a master key
Enabling automatic key rotation
Implementing key expiry
Configuring manual key rotation