AWS Certified Developer Associate DVA-C02 Practice Question
You have been tasked with ensuring that the encryption keys for critical data storage services are automatically renewed periodically in compliance with company policy, which requires key regeneration every 12 months. What is the BEST method to accomplish this for data stored using an Amazon service that allows object storage?
Schedule a CloudWatch Events rule to invoke a function to re-encrypt data in the object storage service using a new encryption key annually
Opt for the default encryption feature of the object storage service to manage key rotation automatically
Develop a routine operation process to generate a new encryption key and manually apply it to the object storage service annually
Set the automatic rotation feature for the customer-managed key in the encryption key management service
The service in question for object storage on Amazon is S3, and the proper way to achieve automatic key rotation is to enable it for the customer-managed key used for encrypting data at rest. By doing so, the key will be automatically rotated on the specified schedule, satisfying the company's internal security policies. The other options provided do not meet the requirement for automatic rotation or apply to different types of key management that do not provide automatic rotation functionality.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a customer-managed key in AWS?
Open an interactive chat with Bash
How does automatic key rotation work in AWS KMS?
Open an interactive chat with Bash
Why wouldn’t using default encryption for S3 satisfy key rotation policies?
Open an interactive chat with Bash
AWS Certified Developer Associate DVA-C02
Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .