Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

A company uses AWS KMS with customer managed keys to encrypt S3 objects. The security team requires automatic key rotation. What must the developer do to enable rotation?

⚠ Common exam trap

DVA-C02 often tests the misconception that KMS rotation is on by default or that AWS managed keys give you configurable rotation — candidates must remember rotation is opt-in only for customer managed keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automatic key rotation in the KMS key settings

Customer managed KMS keys support optional automatic key rotation, which must be explicitly enabled in the key's settings. Once enabled, AWS rotates the backing key material every 365 days (or a custom period of 90–2560 days) while preserving the same key ID, ARN, and alias, so existing ciphertext remains decryptable. Enabling rotation in the KMS key settings is therefore the correct action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS managed keys instead of customer managed keys

    Why it's wrong here

    Using AWS managed keys, while offering automatic rotation, directly contradicts the problem's explicit requirement for customer managed keys (CMKs). CMKs provide greater control over key policies, access management, and auditing, which is often why a company specifically chooses them over AWS managed keys. Therefore, this option fails to meet the fundamental constraint of the question, despite its rotation feature.

  • ✗

    Rotation is enabled by default for all KMS keys

    Why it's wrong here

    Automatic key rotation is not a universal default across all AWS KMS key types. Specifically, Customer Managed Keys (CMKs) require explicit configuration to enable rotation, whereas only AWS managed keys have this feature enabled by default. This option incorrectly generalizes the default behavior, overlooking the critical distinction for CMKs that necessitates an action to enable rotation.

  • ✓

    Enable automatic key rotation in the KMS key settings

    Why this is correct

    For Customer Managed Keys (CMKs), automatic key rotation is an opt-in feature that can be enabled directly within the AWS KMS console or via API calls. Enabling this setting instructs KMS to generate new cryptographic material for the key annually, while retaining the same key ID and ARN. This ensures that data encrypted with the key remains accessible without needing re-encryption, fulfilling the requirement for automatic rotation.

  • ✗

    Create a new key and update the alias to point to the new key annually

    Why it's wrong here

    Creating a new key and manually updating an alias annually constitutes a manual key rotation process, not an automatic one. While this method effectively rotates the underlying cryptographic material and is a valid security practice, it requires administrative intervention and scripting, failing to meet the 'automatic' aspect specified in the problem statement. Automatic rotation for CMKs handles this process transparently within KMS without manual steps.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.