mediumMultiple Choice
CCSP Practice Question: A company uses a cloud provider's key management…
A company uses a cloud provider's key management service. They want to rotate keys automatically every 90 days. What is the correct way to achieve this?
⚠ Common exam trap
ISC2 often tests the misconception that updating a key alias or creating a new key manually is equivalent to automatic rotation, when in fact automatic rotation is a specific KMS feature that preserves key continuity and requires no application changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic key rotation in the KMS settings.
Cloud KMS services (e.g., AWS KMS, Azure Key Vault, GCP Cloud KMS) offer a built-in automatic key rotation feature that can be configured to rotate the key material every 90 days without any manual intervention. Enabling this setting ensures that new cryptographic material is generated for the key, while the old key material remains available for decrypting data encrypted with it, maintaining seamless security compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable automatic key rotation in the KMS settings.
Why this is correct
Enabling automatic key rotation in the KMS settings lets the service generate new key material on a defined schedule, such as every 90 days, without manual intervention. This satisfies the rotation requirement natively, whereas manual rotation would not meet the automated 90-day cadence.
- ✗
Manually update the key alias each quarter.
Why it's wrong here
Manual quarterly alias updates depend on human action, so they are neither automatic nor reliable at the 90-day interval. The KMS rotation setting performs the change on schedule. It is tempting because updating an alias does point applications at new key material, but that approach suits controlled migrations, not automated rotation.
- ✗
Create a new key and update all applications to use it.
Why it's wrong here
Creating a new key and updating applications is manual rotation, not automatic, and leaves old data encrypted under the previous key. Automatic rotation is configured on the existing key via the KMS rotation schedule, which the service performs without application changes.
- ✗
Use a third-party HSM.
Why it's wrong here
A third-party HSM provides key storage and cryptographic operations but does not schedule rotation within the cloud provider's KMS. The KMS's own rotation configuration performs that automatically. It is tempting because HSMs strengthen key custody, which suits compliance requirements for dedicated hardware, not rotation scheduling.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.