Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company is using AWS KMS to encrypt data at rest in Amazon S3. The security team requires that all encryption keys be automatically rotated every year. However, the current KMS key policy does not allow rotation. Which action should the security team take to meet the requirement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an AWS managed key instead of a customer managed key.

AWS managed keys are automatically rotated annually by AWS. This meets the requirement without needing to modify the existing key policy. Option A is wrong because manually rotating the key by creating a new key and updating the S3 bucket policy does not provide automatic rotation and is not the simplest solution. Option C is wrong because customer managed keys with imported key material do not support automatic rotation. Option D is wrong because the existing key policy does not allow rotation, so enabling automatic rotation on that key would fail; the correct approach is to use an AWS managed key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manually rotate the key by creating a new key and updating the S3 bucket policy.

    Why it's wrong here

    Manually rotating the key by creating a new customer managed key and updating the S3 bucket policy does not meet the requirement for automatic rotation. It requires manual steps such as changing the bucket policy, updating aliases, and re-encrypting existing S3 objects, which is error-prone and leaves a window where the old key is no longer used. Furthermore, a one-time manual rotation does not establish a recurring automatic rotation schedule, so it fails the security team's compliance requirement.

  • ✓

    Use an AWS managed key instead of a customer managed key.

    Why this is correct

    Using an AWS managed key such as the aws/s3 key automatically satisfies the rotation requirement because AWS KMS rotates AWS managed keys automatically every year (approximately 365 days) without any customer action. These keys are provisioned and managed by AWS, so the restrictive customer key policy on the existing customer managed key does not apply, and you cannot disable or alter their automatic rotation. For S3 server-side encryption with KMS, simply selecting the aws/s3 managed key encrypts objects with a key that is automatically rotated.

  • ✗

    Create a new customer managed key with imported key material and enable automatic rotation.

    Why it's wrong here

    A customer managed key with imported key material cannot have automatic rotation enabled, so this option is invalid. KMS only supports automatic rotation for keys whose key material is generated by AWS KMS; when you import key material, KMS cannot rotate it because it does not own the cryptographic material and has no way to generate a replacement. To use a customer managed key with imported material, you must manually create a new key and re-import new material, which does not satisfy the automatic rotation requirement.

  • ✗

    Enable automatic rotation on the existing customer managed key.

    Why it's wrong here

    Enabling automatic rotation on the existing customer managed key is blocked by the current key policy, which lacks the kms:EnableKeyRotation permission. The kms:EnableKeyRotation API call requires explicit permission in the key policy, and if the policy denies or omits it, the rotation cannot be turned on. Even though the key material is KMS-generated and therefore technically eligible for rotation, the restrictive policy prevents the action, so a key policy change would be required first—making this option incorrect as stated.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.