Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

Network Topology
key-id 1234abcd-12ab-34cd-56ef-1234567890ab$ aws kms get-key-rotation-statuskey-id 0987fedc-87fe-65dc-43ba-abcdef123456Refer to the exhibit.$ aws kms list-keys"Keys": [{"KeyId": "1234abcd-12ab-34cd-56ef-1234567890ab"},{"KeyId": "0987fedc-87fe-65dc-43ba-abcdef123456"}"KeyRotationEnabled": true"KeyRotationEnabled": false

Refer to the exhibit. A SysOps administrator runs the commands shown. Which key(s) have automatic key rotation enabled?

⚠ Common exam trap

It's easy for candidates to assume automatic key rotation is enabled by default for all KMS keys, but in reality it must be explicitly enabled per key, and the CLI output shows only the first key received the enabling command.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Only the first key

The first key has automatic key rotation enabled because the `EnableKeyRotation` API call was made specifically for that key (key ID `1234abcd-12ab-34cd-56ef-1234567890ab`). AWS KMS automatic key rotation is a per-key setting that must be explicitly enabled; it is not enabled by default. The second key (key ID `0987dcba-09fe-87dc-65ba-0987654321fe`) was not subjected to any rotation-enabling command, so it retains the default disabled state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Only the first key

    Why this is correct

    The first key is the only one that meets the rotation requirement because its KeyRotationEnabled value is true. AWS KMS automatic rotation is enabled on this customer-managed key, meaning AWS replaces the backing key every year. The second key's status is false, so only the first key qualifies.

  • ✗

    Only the second key

    Why it's wrong here

    The second key cannot be the only one because its KeyRotationEnabled flag is false, so it does not have automatic rotation configured. While the first key does have rotation enabled, selecting only the second key ignores that fact. The second key would require a separate enable action to rotate automatically.

  • ✗

    Neither key

    Why it's wrong here

    Neither key is wrong because the first key already has KeyRotationEnabled set to true, which directly indicates automatic rotation is active. This conclusion is based on the returned output from the KMS rotation status command. Therefore, the answer cannot be that neither key has rotation enabled.

  • ✗

    Both keys

    Why it's wrong here

    Both keys is incorrect because the second key's KeyRotationEnabled is false, meaning automatic rotation is not enabled on that key. Only the first key carries the true flag, so the command's output does not support a conclusion that both keys rotate automatically. The second key would need to be enabled for rotation before it also qualifies.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.