SCS-C02 Data Protection Practice Question
A company is using AWS KMS to encrypt data in Amazon Redshift. They need to rotate the KMS key annually. Which approach meets the requirement with minimal operational impact?
⚠ Common exam trap
A common mix-up: candidates think automatic rotation is not available for KMS keys or that they must manually rotate keys using Lambda or by creating new keys, when in fact KMS provides a simple toggle for annual automatic rotation that requires no additional resources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic key rotation on the KMS key
AWS KMS supports automatic annual key rotation for customer-managed KMS keys. Enabling this feature automatically rotates the key material once per year with no manual intervention, minimal operational overhead, and no impact on the Redshift cluster, which continues to use the same key ID.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new KMS key each year and update the Redshift cluster to use the new key
Why it's wrong here
Creating a new KMS key each year and then updating the Redshift cluster to reference it would require modifying cluster settings or performing a snapshot/restore, and any existing tables encrypted with the prior key would need to be re-encrypted to the new one. This approach is manual, likely causes downtime or double-encryption complexity, and increases the chance of losing access to data if the old key is deleted. In contrast, KMS automatic rotation keeps the same key ID and requires no changes to the cluster.
- ✗
Use an AWS Lambda function to rotate the key every year
Why it's wrong here
Running a Lambda function to rotate the key annually is an unnecessary operational burden because KMS already provides built-in automatic rotation for customer managed keys. You would need to set up the function, IAM roles, and a CloudWatch Events schedule, and the function would essentially perform the same action that a single console toggle or AWS CLI update does. Moreover, the function cannot rotate the key for an existing Redshift cluster without cluster-side changes, whereas automatic rotation is fully transparent.
- ✓
Enable automatic key rotation on the KMS key
Why this is correct
Enable automatic rotation on the KMS key. AWS KMS automatically rotates the backing key material one year after the key is created and then every year thereafter, while keeping the same key ID and metadata, so Redshift continues to use the key without any reconfiguration. The old key material is retained to decrypt existing ciphertext, ensuring that all data encrypted under prior versions remains accessible. This meets the requirement of key rotation with minimal effort and no application changes.
- ✗
Rotate the key by re-importing key material into an existing KMS key
Why it's wrong here
Re-importing key material is only possible for KMS keys that were originally imported from your own key material, and it requires you to plan for a manual rotation cycle. You must first schedule deletion of the existing key material, which would make the key temporarily unusable during the rotation window. For a typical Redshift setup that uses AWS-generated key material, this option is not applicable at all; enabling automatic rotation is the intended, low-impact solution.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.