AWS KMS Key Management Best Practices
Which THREE of the following are valid key management features of AWS KMS? (Choose THREE.)
⚠ Common exam trap
Many exam-takers confuse KMS's key management capabilities with other AWS security services, mistakenly thinking KMS handles SSL certificates or password generation, when in reality those are separate services with distinct purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Importing key material
AWS KMS allows you to import your own key material (BYOK) for use with KMS keys, which is a valid key management feature. This is done via the 'ImportKeyMaterial' API, enabling you to create a KMS key with no key material and then upload your own symmetric key material. This feature is essential for meeting compliance requirements that mandate control over the key material lifecycle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Importing key material
Why this is correct
KMS allows you to create a customer managed key with your own cryptographic key material rather than using AWS-generated bytes. This import capability is essential for organizations needing to retain exclusive control over key material to satisfy regulatory or compliance mandates. However, once you import key material, you cannot enable automatic rotation of that KMS key, so you must plan for manual rotation or replacement.
- ✓
Key policies
Why this is correct
KMS key policies are the foundational, resource-based access control documents for customer managed keys, and every KMS key must have one. They specify which IAM principals or AWS services may perform cryptographic operations such as Encrypt, Decrypt, or GenerateDataKey, and which actions like key deletion are allowed. Without an explicit grant in the key policy, other IAM permissions alone cannot grant access to the key, making key policies the primary access control layer.
- ✗
SSL certificate management
Why it's wrong here
SSL/TLS certificate management is handled by AWS Certificate Manager (ACM), not by AWS KMS. KMS does not issue, renew, or deploy public key certificates, nor does it operate as a private or public certificate authority. While both ACM and KMS deal with cryptographic objects, ACM manages the full certificate lifecycle, whereas KMS only manages raw encryption keys and performs low-level cryptographic operations.
- ✗
Password generation
Why it's wrong here
AWS KMS does not generate passwords, user credentials, or other secret text; it produces data keys when you call GenerateDataKey and encrypts or decrypts small data payloads directly. Password generation is a feature of services like AWS Secrets Manager or IAM Identity Center, which internally use KMS only to encrypt the secrets they store. Therefore, using KMS as a password generator would misapply its purpose as a key management and encryption primitive service.
- ✓
Automatic key rotation
Why this is correct
KMS supports automatic rotation for customer managed keys that use AWS-generated key material, creating new backing key material each year without changing the key ID. This rotation preserves existing ciphertext because KMS retains the previous key material for decryption operations, while encryption uses the latest generation. Automatic rotation is optional and can be configured, but it cannot be enabled for asymmetric keys or for keys using imported key material.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.