SOA-C02 Security and Compliance Practice Question
A company uses AWS KMS to encrypt EBS volumes. Which TWO statements about using KMS with EBS are correct? (Choose two.)
⚠ Common exam trap
It's easy for candidates to assume you must specify a KMS key when creating a snapshot, but in reality, the snapshot inherits the encryption from the source volume, and you only need to specify a different key during a copy operation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS managed KMS keys are automatically rotated each year
Option B is correct because AWS managed KMS keys (aws/ebs) are automatically rotated every year (approximately 365 days) with no manual action required. Option C is correct because EBS encryption can use either an AWS managed key (aws/ebs) or a customer managed KMS key that you create and control. Option A is incorrect because EBS encryption requires a symmetric KMS key, and imported key material is not supported for EBS volume encryption. Option D is incorrect because EBS encryption requires symmetric KMS keys; asymmetric KMS keys are not supported for EBS volume encryption. Option E is incorrect because when you create a snapshot, the encryption key is inherited from the source volume (or from the default EBS KMS key if the volume is unencrypted), so you are not required to specify a KMS key at snapshot creation time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
You can import key material for EBS encryption
Why it's wrong here
EBS does support imported key material with customer managed KMS keys.
- ✓
AWS managed KMS keys are automatically rotated each year
Why this is correct
AWS managed keys are rotated annually.
- ✓
EBS can use either customer managed or AWS managed KMS keys
Why this is correct
Both types are supported.
- ✗
EBS supports asymmetric KMS keys
Why it's wrong here
EBS does not support asymmetric keys.
- ✗
You must specify a KMS key when creating a snapshot
Why it's wrong here
You can encrypt a snapshot with a key, but it is not required.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.