Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A security engineer is configuring AWS KMS to encrypt data in a new Amazon S3 bucket. The company requires that the KMS key used for encryption automatically rotate its key material every year, and that the rotation be transparent to applications. The engineer creates a customer managed key with key spec SYMMETRIC_DEFAULT and key usage ENCRYPT_DECRYPT. What should the engineer do next to meet the requirement?

⚠ Common exam trap

The trap here is assuming that automatic key rotation changes the key ID or ARN, or that it is available for all key types.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automatic key rotation on the customer managed key.

AWS KMS customer managed symmetric keys support automatic annual rotation of the backing key material while preserving the same key ID and ARN. This allows existing applications and policies to continue using the key without modification. Enabling automatic rotation satisfies the requirement for transparent yearly rotation. Other options either require manual key replacement, use a key type that does not support rotation, or rely on an AWS managed key that cannot be configured by the customer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable automatic key rotation on the customer managed key.

    Why this is correct

    Automatic key rotation is a feature of AWS KMS customer managed keys that rotates the backing key material annually while retaining the same key ID and ARN. Applications continue to use the same key identifier, and AWS KMS automatically uses the new material for new encryption operations. This meets the requirement for transparent yearly rotation without application changes. The rotation is managed by AWS KMS and requires no additional infrastructure.

  • ✗

    Enable automatic key rotation on the AWS managed key aws/s3.

    Why it's wrong here

    AWS managed keys, such as aws/s3, are managed by AWS and do not support customer-controlled automatic key rotation settings. Their rotation is handled by AWS on a schedule that the customer cannot configure. The scenario requires the engineer to control rotation, which is only possible with customer managed keys. Therefore, using an AWS managed key does not meet the requirement.

  • ✗

    Use an asymmetric KMS key with RSA_2048 and enable automatic rotation.

    Why it's wrong here

    Asymmetric KMS keys do not support automatic key rotation. Only symmetric customer managed keys with ENCRYPT_DECRYPT usage support automatic rotation. Additionally, asymmetric keys are typically used for encryption outside AWS KMS or for digital signatures, not for direct S3 server-side encryption. The requirement is for transparent yearly rotation, which asymmetric keys cannot provide in this context.

  • ✗

    Create a new customer managed key each year and update the S3 bucket policy to use the new key.

    Why it's wrong here

    Creating a new key annually and updating the bucket policy would change the key ID and ARN, requiring applications and policies to be updated. This is not transparent and can cause access issues for existing objects encrypted with the old key. It also adds operational overhead and does not provide automatic rotation. AWS KMS automatic rotation is the intended solution for this requirement.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.