SOA-C02 Security and Compliance Practice Question
Network Topology
Refer to the exhibit. A SysOps administrator runs the commands shown. Which key(s) have automatic key rotation enabled?
⚠ Common exam trap
It's easy for candidates to assume automatic key rotation is enabled by default for all KMS keys, but in reality it must be explicitly enabled per key, and the CLI output shows only the first key received the enabling command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Only the first key
The first key has automatic key rotation enabled because the `EnableKeyRotation` API call was made specifically for that key (key ID `1234abcd-12ab-34cd-56ef-1234567890ab`). AWS KMS automatic key rotation is a per-key setting that must be explicitly enabled; it is not enabled by default. The second key (key ID `0987dcba-09fe-87dc-65ba-0987654321fe`) was not subjected to any rotation-enabling command, so it retains the default disabled state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Only the first key
Why this is correct
The first key is the only one that meets the rotation requirement because its KeyRotationEnabled value is true. AWS KMS automatic rotation is enabled on this customer-managed key, meaning AWS replaces the backing key every year. The second key's status is false, so only the first key qualifies.
- ✗
Only the second key
Why it's wrong here
The second key cannot be the only one because its KeyRotationEnabled flag is false, so it does not have automatic rotation configured. While the first key does have rotation enabled, selecting only the second key ignores that fact. The second key would require a separate enable action to rotate automatically.
- ✗
Neither key
Why it's wrong here
Neither key is wrong because the first key already has KeyRotationEnabled set to true, which directly indicates automatic rotation is active. This conclusion is based on the returned output from the KMS rotation status command. Therefore, the answer cannot be that neither key has rotation enabled.
- ✗
Both keys
Why it's wrong here
Both keys is incorrect because the second key's KeyRotationEnabled is false, meaning automatic rotation is not enabled on that key. Only the first key carries the true flag, so the command's output does not support a conclusion that both keys rotate automatically. The second key would need to be enabled for rotation before it also qualifies.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.