exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 858 discussion

Exam question from Amazon's AWS-SysOps
Question #: 858
Topic #: 1
[All AWS-SysOps Questions]

A SysOps Administrator using AWS KMS needs to rotate all customer master keys (CMKs) every week to meet Information Security guidelines.
Which option would meet the requirement?

  • A. Create a new CMK every 7 days to manually rotate the encryption keys.
  • B. Enable key rotation on the CMKs and set the rotation period to 7 days.
  • C. Switch to using AWS CloudHSM as AWS KMS does not support key rotation.
  • D. Use data keys for each encryption task to avoid the need to rotate keys.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Reference:
https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Newguru2020
Highly Voted 1 year, 7 months ago
Ans: A Since the default automatic rotation period for KMS is 365 days and there is no option to customize it.
upvoted 13 times
r_man
1 year, 7 months ago
Agree.
upvoted 1 times
...
...
Finger41
Most Recent 10 months, 1 week ago
Selected Answer: A
https://docs.aws.amazon.com/kms/latest/developerguide/rotate-keys.html#rotate-aws-managed-keys Customer managed keys Automatic key rotation is disabled by default on customer managed keys but authorized users can enable and disable it. When you enable (or re-enable) automatic key rotation, AWS KMS automatically rotates the KMS key one year (approximately 365 days) after the enable date and every year thereafter. AWS managed keys AWS KMS automatically rotates AWS managed keys every year (approximately 365 days). You cannot enable or disable key rotation for AWS managed keys.
upvoted 1 times
...
abhishek_m_86
1 year, 6 months ago
A. Create a new CMK every 7 days to manually rotate the encryption keys. Seem correct
upvoted 2 times
...
jackdryan
1 year, 6 months ago
I'll go with A
upvoted 1 times
...
MFDOOM
1 year, 6 months ago
A. Create a new CMK every 7 days to manually rotate the encryption keys
upvoted 1 times
...
ImranR
1 year, 6 months ago
A is correct as stated by Newguru2020....
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago