mediumMultiple Select
CCSP Practice Question: A company uses a cloud key management service…
A company uses a cloud key management service (KMS) with automatic key rotation enabled. Which TWO statements about key rotation are true?
⚠ Common exam trap
ISC2 often tests the misconception that key rotation changes the key identifier or requires immediate re-encryption, when in fact the key ID remains stable and old key material is preserved for decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
New key material is generated, and the old key material is retained for decryption.
Option C is correct because KMS rotation generates new cryptographic key material under the same logical key, while the previous key versions are retained so that data encrypted with them can still be decrypted. Option D is correct because applications reference the stable key identifier (key ID/ARN) rather than the underlying key material, so encryption and decryption continue to work transparently without code changes. Option A is wrong because the key ID remains the same; only the backing key material (key version) changes. Option B is wrong because old key material is retained, not immediately destroyed, to preserve the ability to decrypt existing ciphertext. Option E is wrong because re-encryption is not required; old data remains decryptable via the retained old key versions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The key ID changes after each rotation.
Why it's wrong here
Rotation creates a new key version while the key ID or ARN stays constant, so applications referencing that identifier continue working unchanged. It is tempting because per-version identifiers do change, and version-level references are what you would track when auditing which material encrypted a given object.
- ✗
The old key is immediately destroyed after rotation.
Why it's wrong here
Old key versions are retained in a disabled state so existing ciphertext remains decryptable; destruction would render that data permanently unreadable. It is tempting because rotation is often conflated with revocation, which is the correct action when a key is known to be compromised rather than merely aged.
- ✓
New key material is generated, and the old key material is retained for decryption.
Why this is correct
Rotation generates new key material for future encryption while the previous version remains available for decryption, so existing ciphertext stays readable. This retained old material is why rotation does not require re-encrypting all stored data immediately.
- ✓
Applications using the key continue to work without modification.
Why this is correct
Rotation replaces the backing key material while retaining the same key identifier, so ciphertext is re-wrapped transparently and existing references stay valid. Applications continue calling the same key ID, satisfying the stem's automatic rotation constraint without code changes or re-encryption effort.
- ✗
All data encrypted with the old key must be re-encrypted.
Why it's wrong here
KMS stores the key version alongside the ciphertext, so decryption transparently uses the original version; re-encryption is unnecessary. It is tempting because envelope encryption does require rewrapping data keys, which is the correct task when retiring a key version or migrating between key management systems.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.