Courseiva
Security and Compliance →hardMultiple Select

SOA-C02 Security and Compliance Practice Question

A company uses AWS KMS to encrypt EBS volumes. Which TWO statements about using KMS with EBS are correct? (Choose two.)

⚠ Common exam trap

It's easy for candidates to assume you must specify a KMS key when creating a snapshot, but in reality, the snapshot inherits the encryption from the source volume, and you only need to specify a different key during a copy operation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS managed KMS keys are automatically rotated each year

Option B is correct because AWS managed KMS keys (aws/ebs) are automatically rotated every year (approximately 365 days) with no manual action required. Option C is correct because EBS encryption can use either an AWS managed key (aws/ebs) or a customer managed KMS key that you create and control. Option A is incorrect because EBS encryption requires a symmetric KMS key, and imported key material is not supported for EBS volume encryption. Option D is incorrect because EBS encryption requires symmetric KMS keys; asymmetric KMS keys are not supported for EBS volume encryption. Option E is incorrect because when you create a snapshot, the encryption key is inherited from the source volume (or from the default EBS KMS key if the volume is unencrypted), so you are not required to specify a KMS key at snapshot creation time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    You can import key material for EBS encryption

    Why it's wrong here

    EBS does support imported key material with customer managed KMS keys.

  • ✓

    AWS managed KMS keys are automatically rotated each year

    Why this is correct

    AWS managed keys are rotated annually.

  • ✓

    EBS can use either customer managed or AWS managed KMS keys

    Why this is correct

    Both types are supported.

  • ✗

    EBS supports asymmetric KMS keys

    Why it's wrong here

    EBS does not support asymmetric keys.

  • ✗

    You must specify a KMS key when creating a snapshot

    Why it's wrong here

    You can encrypt a snapshot with a key, but it is not required.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.