CompTIA Cloud Essentials+ (CLO-002)Governance, Risk, Compliance and SecurityHard

A cloud security team enforces a policy requiring that all encryption keys protecting sensitive customer data be automatically replaced with new keys every 90 days, with old keys securely retired after a defined grace period. What is the primary security benefit of this practice?

  1. AIt guarantees compliance with all data sovereignty regulations
  2. BIt removes the need for a formal key management policy
  3. CIt limits the amount of data exposed if a single key is ever compromised
  4. DIt eliminates the need for access controls on encrypted data
Show answer & explanation

Correct answer: C. It limits the amount of data exposed if a single key is ever compromised

Key rotation limits the 'blast radius' of a compromised key by reducing the amount of time and data that any single key protects; if a key is compromised, only data encrypted during that key's active window is at risk, not the entire dataset's history.

Why the other options are wrong

  • A. Data sovereignty concerns residency and jurisdiction, which key rotation does not address.
  • B. Key rotation is itself a core component of a key management policy, not a replacement for having one.
  • D. Encryption and rotation do not replace the need for separate access controls like IAM.

Encryption Key Rotation

The practice of periodically replacing cryptographic keys to limit the amount of data exposed if a key is ever compromised, part of the encryption key lifecycle.

  • Reduces the 'blast radius' of a compromised key
  • Old keys are retired/destroyed after a grace period
  • Part of a broader key management lifecycle including generation, storage, and revocation

Memory trick: GDS-RRD: Generate, Distribute, Store, Rotate, Revoke, Destroy

More Governance, Risk, Compliance and Security questions