hardMultiple Choice
CCSP Practice Question: Uses a cloud key management service (KMS) to…
An organization uses a cloud key management service (KMS) to encrypt data at rest. The security policy requires that the encryption keys be rotated every 90 days. The operations team is concerned about the impact of key rotation on encrypted data. Which of the following statements is true regarding KMS key rotation?
⚠ Common exam trap
ISC2 often tests the misconception that key rotation forces re-encryption of all existing data, but the correct understanding is that previous key versions remain available for decryption, making re-encryption optional unless the old key is deleted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data encrypted before rotation can still be decrypted using the previous key as long as it is available
Cloud KMS retains previous key versions after rotation, allowing decryption of data encrypted with older keys. The key rotation creates a new cryptographic key version, but the old version remains active for decryption until it is disabled or deleted. This ensures that data encrypted before rotation remains accessible without re-encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Key rotation is not supported in cloud KMS
Why it's wrong here
Cloud KMS services such as AWS KMS and Azure Key Vault do support automatic key rotation, so this claim is factually false. It may tempt candidates who assume rotation demands manual re-encryption or is unavailable, but rotation is a standard capability configured via rotation policies.
- ✓
Data encrypted before rotation can still be decrypted using the previous key as long as it is available
Why this is correct
Rotating a KMS key creates a new key version while retaining prior versions, so ciphertext stays bound to the version that encrypted it. Decryption therefore continues using that earlier version, provided it remains enabled. This satisfies the 90-day rotation policy without re-encrypting existing data or disrupting access.
- ✗
The KMS automatically re-encrypts all data with the new key
Why it's wrong here
KMS rotation generates a new backing key version; existing ciphertext remains encrypted under the prior version and is not re-encrypted, so no bulk rewrite occurs. Rotation is correct for meeting compliance schedules without touching stored data.
- ✗
Existing data encrypted with the previous key must be re-encrypted with the new key
Why it's wrong here
KMS rotation creates a new key version; older versions remain enabled to decrypt existing ciphertext, so bulk re-encryption is unnecessary. Re-encrypting is only needed when retiring a key version or moving data to a different key entirely, not for routine rotation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.