SCS-C02 Data Protection Practice Question
A company is using AWS KMS to encrypt data at rest in Amazon S3. The security team requires that all encryption keys be automatically rotated every year. However, the current KMS key policy does not allow rotation. Which action should the security team take to meet the requirement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an AWS managed key instead of a customer managed key.
AWS managed keys are automatically rotated annually by AWS. This meets the requirement without needing to modify the existing key policy. Option A is wrong because manually rotating the key by creating a new key and updating the S3 bucket policy does not provide automatic rotation and is not the simplest solution. Option C is wrong because customer managed keys with imported key material do not support automatic rotation. Option D is wrong because the existing key policy does not allow rotation, so enabling automatic rotation on that key would fail; the correct approach is to use an AWS managed key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manually rotate the key by creating a new key and updating the S3 bucket policy.
Why it's wrong here
Manually rotating the key by creating a new customer managed key and updating the S3 bucket policy does not meet the requirement for automatic rotation. It requires manual steps such as changing the bucket policy, updating aliases, and re-encrypting existing S3 objects, which is error-prone and leaves a window where the old key is no longer used. Furthermore, a one-time manual rotation does not establish a recurring automatic rotation schedule, so it fails the security team's compliance requirement.
- ✓
Use an AWS managed key instead of a customer managed key.
Why this is correct
Using an AWS managed key such as the aws/s3 key automatically satisfies the rotation requirement because AWS KMS rotates AWS managed keys automatically every year (approximately 365 days) without any customer action. These keys are provisioned and managed by AWS, so the restrictive customer key policy on the existing customer managed key does not apply, and you cannot disable or alter their automatic rotation. For S3 server-side encryption with KMS, simply selecting the aws/s3 managed key encrypts objects with a key that is automatically rotated.
- ✗
Create a new customer managed key with imported key material and enable automatic rotation.
Why it's wrong here
A customer managed key with imported key material cannot have automatic rotation enabled, so this option is invalid. KMS only supports automatic rotation for keys whose key material is generated by AWS KMS; when you import key material, KMS cannot rotate it because it does not own the cryptographic material and has no way to generate a replacement. To use a customer managed key with imported material, you must manually create a new key and re-import new material, which does not satisfy the automatic rotation requirement.
- ✗
Enable automatic rotation on the existing customer managed key.
Why it's wrong here
Enabling automatic rotation on the existing customer managed key is blocked by the current key policy, which lacks the kms:EnableKeyRotation permission. The kms:EnableKeyRotation API call requires explicit permission in the key policy, and if the policy denies or omits it, the rotation cannot be turned on. Even though the key material is KMS-generated and therefore technically eligible for rotation, the restrictive policy prevents the action, so a key policy change would be required first—making this option incorrect as stated.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.