mediumMultiple ChoiceObjective-mapped
CCSP Practice Question: A company uses a cloud provider's key management…
A company uses a cloud provider's key management service. They want to rotate keys automatically every 90 days. What is the correct way to achieve this?
⚠ Common exam trap
ISC2 often tests the misconception that updating a key alias or creating a new key manually is equivalent to automatic rotation, when in fact automatic rotation is a specific KMS feature that preserves key continuity and requires no application changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic key rotation in the KMS settings.
Cloud KMS services (e.g., AWS KMS, Azure Key Vault, GCP Cloud KMS) offer a built-in automatic key rotation feature that can be configured to rotate the key material every 90 days without any manual intervention. Enabling this setting ensures that new cryptographic material is generated for the key, while the old key material remains available for decrypting data encrypted with it, maintaining seamless security compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable automatic key rotation in the KMS settings.
Why this is correct
Automatic rotation meets the requirement with minimal effort.
- ✗
Manually update the key alias each quarter.
Why it's wrong here
Manual process is error-prone and not automated.
- ✗
Create a new key and update all applications to use it.
Why it's wrong here
This is manual and disruptive.
- ✗
Use a third-party HSM.
Why it's wrong here
HSM does not provide automatic rotation.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.