An organization policy states that all encryption keys must be automatically rotated every 12 months. Which AWS Key Management Service (KMS) key type should be used to meet this requirement?
A.
AWS managed Customer Master Key (CMK)
B.
Customer managed CMK with AWS generated key material
C.
Customer managed CMK with imported key material
Corect answer is sure B . A is wrong since AWS KMS managed CMK is rotated every 3 years by AWs and you cannot change this. for AWS Customer managed CMK with back end keys managed by AWS , it is auto rotation every 12 months , and for AWS customer managed CMKS with imported keys , it must be manual process.So B is 100% right
ANS - A - In May 2022, AWS KMS changed the rotation schedule for AWS managed keys from every three years (approximately 1,095 days) to every year (approximately 365 days).
https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html
APOLOGIZE: "automatic key rotation is optional on customer managed key" and also "AWS KMS automatically rotates AWS managed keys every year (approximately 365 days). You cannot enable or disable key rotation for AWS managed keys."
So right answer should be A instead of B.
Who writes those stupid questions?
Both AWS managed and customer-managed KMS keys are automatically rotated every 12 months.
(maybe that's a really old question, when AWS managed keys auto rotation were every 3 years)
Still LAME question.
This is likely an very dated question. The term" Customer Master Key" is no longer a thing. A It's not AWS KMS Customer "Managed" Key. As such a key can be setup to automatically rotate every year. Same goes for AWS Managed Keys. So the answer is both A and B lol
Side note: You'll need to import your own key material if you want to have more control over rotation. "Rotate" every 90 days for instance.
In May 2022, AWS KMS changed the rotation schedule for AWS managed keys from every three years (approximately 1,095 days) to every year (approximately 365 days).
New AWS managed keys are automatically rotated one year after they are created, and approximately every year thereafter.
Existing AWS managed keys are automatically rotated one year after their most recent rotation, and every year thereafter.
ANS - A - In May 2022, AWS KMS changed the rotation schedule for AWS managed keys from every three years (approximately 1,095 days) to every year (approximately 365 days).
https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html
Correct ans is A. After May 2022, AWS managed CMK must rotates every year by default whereas Customer managed CMK can be rotated every year and it's default rotation is disabled. So in this case option A is better choice than B. Although it's possible with option B too but question says must be automatically rotated.
as of 2022, for AWS Managed key and CMK using KMS, both options are valid with a rotation of 1 year https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html
however, Answer A says AWS managed customer key, i couldn't find any reference with the same name, there is only AWS Managed key , even on portal hence, i will go with Option B
I think the wording of the question is out-dated.
Refer to the below link, I think AWS Managed key = AWS Managed CMK.
https://docs.aws.amazon.com/kms/latest/developerguide/concepts.html
Note
AWS KMS is replacing the term customer master key (CMK) with AWS KMS key and KMS key.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
INASR
Highly Voted 3 years, 6 months agoboooliyooo
Highly Voted 2 years, 5 months agoAWS_Noob
2 years, 2 months agoselim507
2 years, 3 months agoArad
Most Recent 11 months agovirtual
1 year, 2 months agovirtual
1 year, 2 months agoRaphaello
1 year, 2 months ago[Removed]
1 year, 5 months ago[Removed]
1 year, 5 months agoAmy2009
1 year, 8 months agosymplesims
1 year, 9 months agoDavid44
1 year, 9 months agomatrpro
1 year, 11 months agomyLord
2 years, 4 months agoAdamWest
2 years, 5 months agoarae
2 years, 6 months agoQasimac
2 years, 6 months agoHieuTT
2 years, 5 months agowelcomeYM
2 years, 6 months agowelcomeYM
2 years, 6 months agowelcomeYM
2 years, 6 months agomadcloud
2 years, 6 months agolyzy0906
2 years, 5 months ago