passdrill
AWS SAA-C03 · IAM & Security · Card 019/024 hard

A team enables automatic key rotation, using the default settings, on a symmetric customer managed KMS key whose key material AWS KMS generated. They also have a separate asymmetric customer managed KMS key that they would like to rotate on a similar automatic schedule. What should they expect?

  1. The symmetric key rotates automatically every 365 days unless a custom rotation period between 90 and 2560 days is specified; the asymmetric key is not eligible for automatic or on-demand rotation and must instead be rotated manually by creating a new key and updating references to it
  2. Both keys rotate automatically every 365 days once automatic rotation is enabled, because AWS KMS treats every customer managed key type identically for rotation purposes
  3. Neither key can ever have its key material rotated after creation; the only way to rotate is to close the account and open a new one
  4. The asymmetric key rotates automatically every 90 days by default, while the symmetric key requires manual rotation because it holds the material actually used to encrypt data
Next card → Shuffle