DVA-C02 Security Practice Question
A company uses AWS KMS with customer managed keys to encrypt S3 objects. The security team requires automatic key rotation. What must the developer do to enable rotation?
⚠ Common exam trap
DVA-C02 often tests the misconception that KMS rotation is on by default or that AWS managed keys give you configurable rotation — candidates must remember rotation is opt-in only for customer managed keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic key rotation in the KMS key settings
Customer managed KMS keys support optional automatic key rotation, which must be explicitly enabled in the key's settings. Once enabled, AWS rotates the backing key material every 365 days (or a custom period of 90–2560 days) while preserving the same key ID, ARN, and alias, so existing ciphertext remains decryptable. Enabling rotation in the KMS key settings is therefore the correct action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS managed keys instead of customer managed keys
Why it's wrong here
Using AWS managed keys, while offering automatic rotation, directly contradicts the problem's explicit requirement for customer managed keys (CMKs). CMKs provide greater control over key policies, access management, and auditing, which is often why a company specifically chooses them over AWS managed keys. Therefore, this option fails to meet the fundamental constraint of the question, despite its rotation feature.
- ✗
Rotation is enabled by default for all KMS keys
Why it's wrong here
Automatic key rotation is not a universal default across all AWS KMS key types. Specifically, Customer Managed Keys (CMKs) require explicit configuration to enable rotation, whereas only AWS managed keys have this feature enabled by default. This option incorrectly generalizes the default behavior, overlooking the critical distinction for CMKs that necessitates an action to enable rotation.
- ✓
Enable automatic key rotation in the KMS key settings
Why this is correct
For Customer Managed Keys (CMKs), automatic key rotation is an opt-in feature that can be enabled directly within the AWS KMS console or via API calls. Enabling this setting instructs KMS to generate new cryptographic material for the key annually, while retaining the same key ID and ARN. This ensures that data encrypted with the key remains accessible without needing re-encryption, fulfilling the requirement for automatic rotation.
- ✗
Create a new key and update the alias to point to the new key annually
Why it's wrong here
Creating a new key and manually updating an alias annually constitutes a manual key rotation process, not an automatic one. While this method effectively rotates the underlying cryptographic material and is a valid security practice, it requires administrative intervention and scripting, failing to meet the 'automatic' aspect specified in the problem statement. Automatic rotation for CMKs handles this process transparently within KMS without manual steps.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.