Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

Network Topology
aws cloudtrail create-trailname my-trails3-bucket-name my-bucketenable-log-file-validationkms-key-id arn:aws:kms:us-east-1:123456789012:key/abc123Refer to the exhibit.

A DevOps engineer executed the CLI command shown in the exhibit. After creation, the security team requires that the log files be encrypted with a KMS key that is rotated every 90 days. The current key is a customer managed key with automatic rotation enabled set to 365 days. What should the engineer do to meet the requirement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a new KMS key with automatic rotation set to 90 days and update the trail with the new key

The requirement is to encrypt log files with a KMS key that rotates every 90 days. The current key rotates every 365 days, and you cannot change the rotation period of an existing customer managed key; you must create a new key with the desired rotation period. Once created, you update the CloudTrail trail to use the new key by specifying the --kms-key-id parameter. Option D correctly describes this process. Option A is wrong because you cannot change the rotation period of an existing key. Option B is wrong because manually rotating a key does not meet the automatic rotation requirement and is not recommended. Option C is wrong because you cannot modify the rotation period of an existing key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the existing key and change the rotation period in KMS

    Why it's wrong here

    The rotation period of an existing customer managed key is immutable; AWS KMS does not support modifying `RotationPeriodInDays` after key creation. The only API operations available are `EnableKeyRotation` and `DisableKeyRotation`, which toggle automatic rotation without allowing you to change the interval. Therefore, you cannot adjust the existing key used by CloudTrail to a 90-day rotation schedule.

  • ✗

    Disable automatic rotation and manually rotate the key every 90 days

    Why it's wrong here

    Disabling automatic rotation and manually rotating the key every 90 days does not meet the requirement because AWS KMS will not rotate the backing key material, and CloudTrail continues using the same key ARN, so the effective encryption key never changes. You would have to create a new key, update the trail to use it, and update permissions each time—an error-prone process that still relies on human intervention and cannot be considered automatic rotation for compliance.

  • ✗

    Modify the KMS key to set the rotation period to 90 days

    Why it's wrong here

    The AWS KMS console and APIs allow you to specify `RotationPeriodInDays` only in the `CreateKey` (or `create-key`) call; after creation, this value is fixed. You cannot invoke `UpdateKeyRotationPeriod` (no such API) or modify the key via `PutKeyPolicy` or `UpdateKeyDescription` to change the 90-day period, so attempting to modify the existing key is not possible.

  • ✓

    Create a new KMS key with automatic rotation set to 90 days and update the trail with the new key

    Why this is correct

    To achieve a 90-day automatic rotation, you must create a new symmetric customer managed key with `--rotation-period-in-days 90` in the `create-key` CLI call and then associate it with the trail using `update-trail --kms-key-id <new-key-arn>`. After updating, CloudTrail will use the new key to encrypt future log files, and the new key's key policy must include CloudTrail's account and the required `kms:GenerateDataKey` and `kms:Decrypt` permissions. Existing log files remain encrypted under the old key, so that key should still be available for decryption.

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.