Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company has a requirement to automatically rotate encryption keys for Amazon EBS volumes every 90 days. The EBS volumes are encrypted using AWS KMS. What is the simplest way to meet this requirement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a new KMS key every 90 days and re-encrypt volumes using a script.

KMS automatic key rotation creates new backing keys yearly, not every 90 days. To meet the 90-day rotation requirement, you must manually create a new KMS key every 90 days and then re-encrypt the EBS volumes (e.g., by taking a snapshot, copying it with the new key, and restoring). Option A is incorrect because AWS Secrets Manager manages secrets, not KMS keys; it cannot rotate KMS keys. Option C is incorrect because client-side encryption would require managing keys outside of KMS, which adds complexity and does not meet the requirement of using AWS KMS. Option D is incorrect because automatic key rotation on the existing KMS key only rotates the backing key once per year, not every 90 days.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS Secrets Manager to rotate the KMS key automatically.

    Why it's wrong here

    AWS Secrets Manager is designed to rotate stored secrets such as database credentials, not KMS customer master keys. While a secret can be encrypted with a customer-managed KMS key, Secrets Manager has no API to rotate that KMS key itself. The requirement is to rotate the EBS volume encryption key every 90 days, which Secrets Manager cannot do; it would at most rotate the secret value, and the KMS key would remain unchanged.

  • ✓

    Create a new KMS key every 90 days and re-encrypt volumes using a script.

    Why this is correct

    To satisfy a 90-day rotation requirement, you must perform manual key rotation by creating a new KMS key every 90 days and then re-encrypting your EBS volumes with that new key. A typical scripted approach creates an encrypted snapshot of each volume using the new key, creates a new volume from that snapshot, and attaches it to the instance after detaching the old volume. This changes the actual key ID and re-encrypts the volume data, which is the only way to meet a sub-yearly rotation schedule because KMS automatic rotation only occurs every year.

  • ✗

    Switch to client-side encryption and rotate keys manually.

    Why it's wrong here

    EBS does not natively support client-side encryption; encryption for EBS volumes is implemented server-side at the Amazon-managed storage layer. Moving to client-side encryption would require you to build encryption into your application, and even then the underlying EBS volume would still need its own encryption to protect the data at rest, so it doesn't eliminate the need to manage KMS keys for EBS. Additionally, client-side encryption with your own keys would be a separate mechanism and would not meet the requirement to rotate the EBS volume encryption keys.

  • ✗

    Enable automatic key rotation on the existing KMS key.

    Why it's wrong here

    Enabling automatic key rotation on an existing customer-managed KMS key rotates the backing key material only after a full year, and the key ID remains unchanged. This interval does not satisfy the 90-day rotation requirement, and the rotation of key material does not re-encrypt data already encrypted by the key — EBS volumes will still reference the same key with no re-encryption. To achieve 90-day rotation, you must create a new KMS key and re-encrypt the volumes, as key material rotation alone is insufficient.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.