Courseiva
Security →mediumMultiple Choice

DVA-C02 Security Practice Question

Network Topology
$ aws kms describe-keykey-id 1234abcd-12ab-34cd-56ef-1234567890abRefer to the exhibit.$ aws kms list-keys"Keys": ["KeyId": "1234abcd-12ab-34cd-56ef-1234567890ab","KeyArn": "arn:aws:kms:us-east-1:123456789012:key/1234abcd-12ab-34cd-56ef-1234567890ab""KeyMetadata": {"KeyManager": "CUSTOMER","KeyState": "Disabled"

A developer runs the commands above. The key is disabled. An application that uses this key to encrypt S3 objects starts failing. What should the developer do to fix the issue?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the KMS key

Enable the KMS key. The key is disabled, so enabling it will restore functionality. Option A (delete the key and recreate it) would create a new key, but the application would need to be updated to use the new key, which is unnecessary since the original key exists and can simply be re-enabled. Option B (create a new KMS key and update the application to use it) is also a valid but more complex fix; however, the simplest and most direct solution is to re-enable the key. Option D (enable automatic key rotation) does not affect the disabled state; it only sets a rotation policy for future key updates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete the key and recreate it

    Why it's wrong here

    Deleting an AWS KMS key is an irreversible action that permanently removes the key material, making all data previously encrypted with that specific key unrecoverable unless a backup of the plaintext or a different encryption key was used. Recreating a key with the same alias does not restore access to the original encrypted data, as it generates entirely new cryptographic material. This is a destructive and unnecessary step when the key can simply be re-enabled.

  • ✗

    Create a new KMS key and update the application to use it

    Why it's wrong here

    Creating a new KMS key would indeed provide a functional key for future encryption, but it does not address the data already encrypted with the *disabled* key, which would remain inaccessible. Furthermore, it necessitates updating the application's configuration to reference the new key and potentially migrating existing data, incurring significant development and operational overhead. This approach is far more complex than simply re-enabling the existing key.

  • ✓

    Enable the KMS key

    Why this is correct

    When an AWS KMS key is disabled, it transitions into a `Disabled` state, preventing any cryptographic operations such as encryption or decryption. Enabling the KMS key directly changes its state back to `Enabled`, immediately restoring its full functionality. This allows the application to resume using the key for all authorized cryptographic operations without requiring any changes to application code or data migration, making it the most direct and efficient solution.

  • ✗

    Enable automatic key rotation

    Why it's wrong here

    Enabling automatic key rotation is a security best practice that periodically generates new cryptographic material for a KMS key, ensuring that even if older material is compromised, only a limited amount of data is affected. However, key rotation does not affect the operational status of a KMS key. A disabled key will remain disabled and unusable for cryptographic operations, regardless of whether new key material is being generated in the background.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.