exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 34 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 34
Topic #: 1
[All AWS Certified Security - Specialty Questions]

An organization policy states that all encryption keys must be automatically rotated every 12 months.
Which AWS Key Management Service (KMS) key type should be used to meet this requirement?

  • A. AWS managed Customer Master Key (CMK)
  • B. Customer managed CMK with AWS generated key material
  • C. Customer managed CMK with imported key material
  • D. AWS managed data key
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
INASR
Highly Voted 3 years, 6 months ago
Corect answer is sure B . A is wrong since AWS KMS managed CMK is rotated every 3 years by AWs and you cannot change this. for AWS Customer managed CMK with back end keys managed by AWS , it is auto rotation every 12 months , and for AWS customer managed CMKS with imported keys , it must be manual process.So B is 100% right
upvoted 50 times
...
boooliyooo
Highly Voted 2 years, 5 months ago
Selected Answer: A
ANS - A - In May 2022, AWS KMS changed the rotation schedule for AWS managed keys from every three years (approximately 1,095 days) to every year (approximately 365 days). https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html
upvoted 24 times
AWS_Noob
2 years, 2 months ago
Outdated question. But if it features, A would be correct
upvoted 3 times
...
selim507
2 years, 3 months ago
Agreed!
upvoted 2 times
...
...
Arad
Most Recent 11 months ago
Selected Answer: B
Correct answer is B.
upvoted 1 times
...
virtual
1 year, 2 months ago
Selected Answer: B
Safe response is B: "AWS KMS supports automatic key rotation only for symmetric encryption KMS keys with key material that AWS KMS creates".
upvoted 1 times
virtual
1 year, 2 months ago
APOLOGIZE: "automatic key rotation is optional on customer managed key" and also "AWS KMS automatically rotates AWS managed keys every year (approximately 365 days). You cannot enable or disable key rotation for AWS managed keys." So right answer should be A instead of B.
upvoted 1 times
...
...
Raphaello
1 year, 2 months ago
Selected Answer: B
Who writes those stupid questions? Both AWS managed and customer-managed KMS keys are automatically rotated every 12 months. (maybe that's a really old question, when AWS managed keys auto rotation were every 3 years) Still LAME question.
upvoted 2 times
...
[Removed]
1 year, 5 months ago
This is likely an very dated question. The term" Customer Master Key" is no longer a thing. A It's not AWS KMS Customer "Managed" Key. As such a key can be setup to automatically rotate every year. Same goes for AWS Managed Keys. So the answer is both A and B lol Side note: You'll need to import your own key material if you want to have more control over rotation. "Rotate" every 90 days for instance.
upvoted 1 times
[Removed]
1 year, 5 months ago
Correction: it's NOW AWS KMS Customer "Managed" Key
upvoted 1 times
...
...
Amy2009
1 year, 8 months ago
B. B is correct.
upvoted 1 times
...
symplesims
1 year, 9 months ago
Selected Answer: B A incorrect - CMK is not Customer Master Key.
upvoted 1 times
...
David44
1 year, 9 months ago
Answers are A and B !!
upvoted 2 times
...
matrpro
1 year, 11 months ago
Selected Answer: A
In May 2022, AWS KMS changed the rotation schedule for AWS managed keys from every three years (approximately 1,095 days) to every year (approximately 365 days). New AWS managed keys are automatically rotated one year after they are created, and approximately every year thereafter. Existing AWS managed keys are automatically rotated one year after their most recent rotation, and every year thereafter.
upvoted 3 times
...
myLord
2 years, 4 months ago
"B" is the answer because The “Automated Key Rotation” option for KMS appears for AWS KMS generated key material.
upvoted 1 times
...
AdamWest
2 years, 5 months ago
Selected Answer: A
ANS - A - In May 2022, AWS KMS changed the rotation schedule for AWS managed keys from every three years (approximately 1,095 days) to every year (approximately 365 days). https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html
upvoted 7 times
...
arae
2 years, 6 months ago
Its A now after the latest changes look into this doc https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html
upvoted 4 times
...
Qasimac
2 years, 6 months ago
Correct ans is A. After May 2022, AWS managed CMK must rotates every year by default whereas Customer managed CMK can be rotated every year and it's default rotation is disabled. So in this case option A is better choice than B. Although it's possible with option B too but question says must be automatically rotated.
upvoted 5 times
HieuTT
2 years, 5 months ago
nice answer
upvoted 1 times
...
...
welcomeYM
2 years, 6 months ago
Selected Answer: B
BBBBBBBB
upvoted 1 times
...
welcomeYM
2 years, 6 months ago
Selected Answer: A
AAAAAAAA
upvoted 3 times
welcomeYM
2 years, 6 months ago
Please remove it.
upvoted 1 times
...
...
madcloud
2 years, 6 months ago
as of 2022, for AWS Managed key and CMK using KMS, both options are valid with a rotation of 1 year https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html however, Answer A says AWS managed customer key, i couldn't find any reference with the same name, there is only AWS Managed key , even on portal hence, i will go with Option B
upvoted 5 times
lyzy0906
2 years, 5 months ago
I think the wording of the question is out-dated. Refer to the below link, I think AWS Managed key = AWS Managed CMK. https://docs.aws.amazon.com/kms/latest/developerguide/concepts.html Note AWS KMS is replacing the term customer master key (CMK) with AWS KMS key and KMS key.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago