AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A DevOps engineer rotated a customer-managed KMS key alias that encrypts the Amazon EBS root volume of an Auto Scaling group. The alias now points to a new CMK, and the original CMK is disabled. New EC2 instances launch, but existing instances fail to start because their root volumes cannot be decrypted. What is the MOST operationally efficient way to restore the affected instances?
Copy every existing snapshot to the new CMK and launch replacement instances from the copied snapshots.
Update the launch template to reference the new CMK and perform an instance refresh on the Auto Scaling group.
Re-enable the disabled CMK to allow KMS to decrypt the existing volumes, then start the instances.
Detach each root volume, create an unencrypted snapshot, then re-encrypt the snapshot with the new CMK and reattach the volume.
The existing root volumes remain encrypted with the original customer-managed CMK. After the key was disabled, AWS KMS stopped decrypting requests that occur when a stopped instance starts and the volume is re-attached. Re-enabling the disabled CMK immediately makes it usable again, allowing Amazon EBS to decrypt the data keys and boot the instances. The other options require recreating or copying each volume or snapshot, adding unnecessary operational effort.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a customer-managed KMS key (CMK)?
Open an interactive chat with Bash
Why does disabling a CMK cause issues with encrypted Amazon EBS volumes?
Open an interactive chat with Bash
How does re-enabling a disabled CMK help resolve this issue with EBS volumes?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .