Courseiva

SCS-C02 Identity and Access Management Practice Question

Drag and drop the steps to implement AWS KMS key rotation in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a CMK, then enable automatic key rotation, then perform manual key rotation (if needed), then update applications to use the new key, then verify decryption.

Key rotation starts with creating a CMK, enabling auto-rotation, manual rotation if needed, updating apps, and verifying decryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a CMK, then enable automatic key rotation, then perform manual key rotation (if needed), then update applications to use the new key, then verify decryption.

    Why this is correct

    This is the correct order because you must first create the CMK, then enable automatic rotation to rotate the backing key annually. If immediate rotation is needed, you perform manual rotation (creating a new CMK), then update applications to use the new key, and finally verify decryption to ensure the new key works.

  • ✗

    Create a CMK, then perform manual key rotation, then enable automatic key rotation, then update applications to use the new key, then verify decryption.

    Why it's wrong here

    This sequence reverses the intended control-plane actions. Manual key rotation in KMS means creating a brand-new CMK (or new key material) and reassigning aliases, whereas automatic rotation changes the backing key of the same CMK while preserving the key ID. If you manually rotate first, you are working with a new CMK before you have set up automatic rotation on the original one, so your automatic rotation enablement either targets the wrong key or is applied after you have already committed to a new key identity. Enabling automatic rotation should immediately follow CMK creation so the original key's backing material rotates annually; manual rotation should only be considered later if immediate re-keying is required, not as a precursor to the automatic-rotation setting.

  • ✗

    Enable automatic key rotation, then create a CMK, then perform manual key rotation, then update applications, then verify decryption.

    Why it's wrong here

    Automatic key rotation cannot be enabled before the CMK exists because the EnableKeyRotation API call requires an existing KeyId or AliasName to identify the target key. Without a CMK, there is no rotating key material, no alias to reference, and no IAM/Key Policy context for the rotation permission. The very first step must be creating a customer-managed key (or importing key material if applicable), and only then can you configure rotation policies such as automatic annual rotation. Additionally, this option omits the prerequisite of establishing a rooted KMS key policy that allows the account to manage rotation, so the order is not only operationally impossible but also lacks the required access-control setup before rotation settings are applied.

  • ✗

    Create a CMK, then enable automatic key rotation, then update applications to use the new key, then perform manual key rotation, then verify decryption.

    Why it's wrong here

    This is incorrect because you should perform manual key rotation before updating applications. Manual rotation creates a new key that applications will use; updating applications before manual rotation means they would still reference the old key.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.