An organization uses AWS Key Management Service (KMS) with customer-managed keys. The security policy requires automatic key rotation every year. A DevOps engineer notices that the key material is not rotating as expected. What is the most likely cause?
An AWS KMS customer master key with imported key material (Origin: EXTERNAL) cannot have automatic key rotation enabled, because rotation relies on the key material being generated and managed within AWS KMS. The import mechanism bypasses KMS's managed backing keys, so the service cannot automatically replace the backing key. To rotate such a key, you must manually create a new CMK or import new key material into the existing CMK.
Why this answer
Automatic key rotation is not supported for imported key material. Option B is wrong because KMS does not charge extra for automatic rotation. Option C is wrong because KMS does not require re-importing for rotation; it's simply not available.
Option D is wrong because the key state does not prevent rotation.