DVA-C02 Security Practice Question
Network Topology
A developer runs the commands above. The key is disabled. An application that uses this key to encrypt S3 objects starts failing. What should the developer do to fix the issue?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the KMS key
Enable the KMS key. The key is disabled, so enabling it will restore functionality. Option A (delete the key and recreate it) would create a new key, but the application would need to be updated to use the new key, which is unnecessary since the original key exists and can simply be re-enabled. Option B (create a new KMS key and update the application to use it) is also a valid but more complex fix; however, the simplest and most direct solution is to re-enable the key. Option D (enable automatic key rotation) does not affect the disabled state; it only sets a rotation policy for future key updates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the key and recreate it
Why it's wrong here
Deleting an AWS KMS key is an irreversible action that permanently removes the key material, making all data previously encrypted with that specific key unrecoverable unless a backup of the plaintext or a different encryption key was used. Recreating a key with the same alias does not restore access to the original encrypted data, as it generates entirely new cryptographic material. This is a destructive and unnecessary step when the key can simply be re-enabled.
- ✗
Create a new KMS key and update the application to use it
Why it's wrong here
Creating a new KMS key would indeed provide a functional key for future encryption, but it does not address the data already encrypted with the *disabled* key, which would remain inaccessible. Furthermore, it necessitates updating the application's configuration to reference the new key and potentially migrating existing data, incurring significant development and operational overhead. This approach is far more complex than simply re-enabling the existing key.
- ✓
Enable the KMS key
Why this is correct
When an AWS KMS key is disabled, it transitions into a `Disabled` state, preventing any cryptographic operations such as encryption or decryption. Enabling the KMS key directly changes its state back to `Enabled`, immediately restoring its full functionality. This allows the application to resume using the key for all authorized cryptographic operations without requiring any changes to application code or data migration, making it the most direct and efficient solution.
- ✗
Enable automatic key rotation
Why it's wrong here
Enabling automatic key rotation is a security best practice that periodically generates new cryptographic material for a KMS key, ensuring that even if older material is compromised, only a limited amount of data is affected. However, key rotation does not affect the operational status of a KMS key. A disabled key will remain disabled and unusable for cryptographic operations, regardless of whether new key material is being generated in the background.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.