AWS Certified Solutions Architect Associate SAA-C03 Practice Question

A financial institution uses AWS Key Management Service (AWS KMS) to encrypt data at rest. Company policy requires that the underlying cryptographic material be renewed automatically while keeping the same key ID and metadata. Which approach will satisfy this requirement?

  • Manually create a new KMS key every five years and disable the prior key.

  • Enable automatic key rotation for the customer-managed KMS key by using the AWS KMS console, CLI, or API.

  • Postpone rotation until the key approaches its scheduled deletion or expiration date.

  • Rotate the key material only if a security incident indicates the key may be compromised.

AWS Certified Solutions Architect Associate SAA-C03
Design Secure Architectures
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot