Courseiva
Data Protection →hardMultiple Select

AWS KMS Key Management Best Practices

Which THREE of the following are valid key management features of AWS KMS? (Choose THREE.)

⚠ Common exam trap

Many exam-takers confuse KMS's key management capabilities with other AWS security services, mistakenly thinking KMS handles SSL certificates or password generation, when in reality those are separate services with distinct purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Importing key material

AWS KMS allows you to import your own key material (BYOK) for use with KMS keys, which is a valid key management feature. This is done via the 'ImportKeyMaterial' API, enabling you to create a KMS key with no key material and then upload your own symmetric key material. This feature is essential for meeting compliance requirements that mandate control over the key material lifecycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Importing key material

    Why this is correct

    KMS allows you to create a customer managed key with your own cryptographic key material rather than using AWS-generated bytes. This import capability is essential for organizations needing to retain exclusive control over key material to satisfy regulatory or compliance mandates. However, once you import key material, you cannot enable automatic rotation of that KMS key, so you must plan for manual rotation or replacement.

  • ✓

    Key policies

    Why this is correct

    KMS key policies are the foundational, resource-based access control documents for customer managed keys, and every KMS key must have one. They specify which IAM principals or AWS services may perform cryptographic operations such as Encrypt, Decrypt, or GenerateDataKey, and which actions like key deletion are allowed. Without an explicit grant in the key policy, other IAM permissions alone cannot grant access to the key, making key policies the primary access control layer.

  • ✗

    SSL certificate management

    Why it's wrong here

    SSL/TLS certificate management is handled by AWS Certificate Manager (ACM), not by AWS KMS. KMS does not issue, renew, or deploy public key certificates, nor does it operate as a private or public certificate authority. While both ACM and KMS deal with cryptographic objects, ACM manages the full certificate lifecycle, whereas KMS only manages raw encryption keys and performs low-level cryptographic operations.

  • ✗

    Password generation

    Why it's wrong here

    AWS KMS does not generate passwords, user credentials, or other secret text; it produces data keys when you call GenerateDataKey and encrypts or decrypts small data payloads directly. Password generation is a feature of services like AWS Secrets Manager or IAM Identity Center, which internally use KMS only to encrypt the secrets they store. Therefore, using KMS as a password generator would misapply its purpose as a key management and encryption primitive service.

  • ✓

    Automatic key rotation

    Why this is correct

    KMS supports automatic rotation for customer managed keys that use AWS-generated key material, creating new backing key material each year without changing the key ID. This rotation preserves existing ciphertext because KMS retains the previous key material for decryption operations, while encryption uses the latest generation. Automatic rotation is optional and can be configured, but it cannot be enabled for asymmetric keys or for keys using imported key material.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.