Courseiva

How to Prevent AWS KMS Key Deletion Using Key Policies

A data engineer receives an alert that an AWS KMS key has been scheduled for deletion by mistake. What is the immediate action to prevent the key from being deleted?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cancel the key deletion from the KMS console or API.

When a KMS key is scheduled for deletion, the deletion can be canceled from the AWS KMS console or via the CancelKeyDeletion API during the pending deletion period. This immediate action restores the key to its previous state and prevents it from being deleted. Option B is incorrect because creating a new key does not cancel the deletion of the existing key. Option C is incorrect because deleted KMS keys cannot be restored; the default waiting period of 7–30 days exists specifically to allow cancellation. Option D is incorrect because disabling the key does not affect the deletion schedule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cancel the key deletion from the KMS console or API.

    Why this is correct

    Cancelling the scheduled deletion via the KMS console or API immediately halts the pending deletion window, satisfying the stem's requirement to prevent the key from being destroyed. AWS KMS permits cancellation at any point during the mandatory waiting period, restoring the key to a usable state before permanent deletion occurs.

  • ✗

    Create a new KMS key and re-encrypt the data.

    Why it's wrong here

    Creating a new key and re-encrypting does not cancel the pending deletion of the original key, which still destroys data encrypted under it. Re-encryption is tempting as a resilience measure, and it would be correct for planned key replacement — not for rescuing a key already scheduled for deletion.

  • ✗

    Wait for the key to be deleted and restore it from backup.

    Why it's wrong here

    Waiting allows the key to be deleted; AWS KMS keys cannot be restored from backup, so data encrypted under them becomes unrecoverable. Backup restoration is tempting from general data-protection habits, and it would be correct for other AWS resources — not for KMS keys.

  • ✗

    Disable the key immediately to stop usage.

    Why it's wrong here

    Disabling a KMS key blocks cryptographic operations but does not cancel the scheduled deletion; the key still enters Pending Deletion and is destroyed after the waiting period. Cancelling the deletion restores the key to Enabled. Disabling suits temporary suspension of key usage, not reversing a deletion schedule.

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.