SCS-C02 Data Protection Practice Question
A company uses AWS KMS to encrypt data at rest in Amazon S3. The security team requires that all encryption keys be automatically rotated every year. Which solution meets this requirement?
⚠ Common exam trap
Many candidates assume AWS managed keys can be configured for automatic rotation with a custom period, but in reality, AWS managed keys have a fixed three-year rotation schedule and cannot be adjusted, making customer managed keys the only option for yearly rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a customer managed key and enable automatic rotation with a yearly rotation period.
Customer managed keys (CMKs) in AWS KMS support automatic rotation with a customizable rotation period, which can be set to 365 days (one year) to meet the security team's requirement. AWS managed keys, on the other hand, have a fixed automatic rotation period of every three years (1095 days) and cannot be adjusted, making them unsuitable for a yearly rotation mandate. By using a CMK with automatic rotation enabled and specifying a rotation period of one year, the company ensures that the encryption key material is rotated annually without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an AWS managed key and enable automatic rotation.
Why it's wrong here
AWS managed keys already have automatic rotation enabled by the service, so enabling it is not an action you can take; more importantly, their fixed rotation schedule is not aligned with a yearly requirement, as AWS rotates these keys on a longer fixed cycle rather than annually. This option fails because you have no configuration control over the rotation period of an AWS managed key, and the stated yearly requirement would not be met.
- ✗
Use a customer managed key with imported key material and enable automatic rotation.
Why it's wrong here
Although a customer managed key is the right key family, imported key material disqualifies it from automatic rotation; KMS does not support automatic rotation for symmetric customer managed keys whose key material was imported. To use automatic rotation with a 365-day period, the key material must be generated and maintained by AWS KMS. This option therefore cannot meet the company's yearly rotation goal.
- ✓
Use a customer managed key and enable automatic rotation with a yearly rotation period.
Why this is correct
A customer managed key provides the administrative control needed to satisfy the requirement, and KMS supports automatic rotation with a configurable period between 90 and 2560 days for symmetric keys generated in KMS. By creating a customer managed key with KMS-generated key material and setting its automatic rotation period to 365 days, the company achieves seamless annual rotation while decrypting data with previous key versions as needed.
- ✗
Use an AWS managed key and manually rotate it every year.
Why it's wrong here
Manual rotation of an AWS managed key is not a supported operation because AWS owns and manages the entire lifecycle of these keys. You cannot create a new key version, replace key material, or trigger rotation on demand for an AWS managed key; only customer managed keys support manual rotation through alias updates or new key creation. Therefore, attempting to manually rotate an AWS managed key each year is invalid and cannot satisfy the compliance requirement.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.