AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium

A company uses an AWS KMS customer managed key to encrypt sensitive data and wants the underlying key material rotated automatically every year without needing to update any application code that references the key. Which KMS capability satisfies this requirement?

  1. AManually deleting and recreating the key annually
  2. BKey policies
  3. CEnvelope encryption
  4. DAutomatic key rotation
Show answer & explanation

Correct answer: D. Automatic key rotation

KMS automatic key rotation generates new cryptographic material for a customer managed key roughly once a year while keeping the same key ID, so applications do not need any changes. Manually deleting a key would break references to it entirely.

Why the other options are wrong

  • A. Deleting a key would invalidate applications referencing it, unlike rotation.
  • B. Key policies control access permissions, not rotation.
  • C. Envelope encryption describes how KMS encrypts data keys, not rotation behavior.

KMS Automatic Key Rotation

AWS KMS can automatically rotate the cryptographic material of a customer managed key approximately every year while preserving the key ID and ARN.

  • Rotation keeps the same key ID so apps need no changes
  • Applies to customer managed KMS keys (optional, enabled per key)
  • AWS managed keys rotate automatically every year by default

Memory trick: Same lock, new key teeth every year

More Security and Compliance questions