A company uses AWS Key Management Service (AWS KMS). When attempting to attach an encrypted Amazon Elastic Block Store (Amazon EBS) volume to an Amazon EC2 instance, the attachment fails. The company discovers that a customer managed key has become unusable because its imported key material was deleted. The data on the EBS volume is needed. A security engineer must recommend a way to decrypt the volume’s encrypted data key and attach the volume. Which solution will meet these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Reimport the exact same key material that was originally imported into the KMS key. Attach the EBS volume..
Why this is the answer
The correct solution is to reimport the exact same key material because AWS KMS allows reimporting key material for an existing KMS key if it was originally imported. This restores the KMS key to its functional state, enabling it to decrypt the data key associated with the EBS volume. The EBS volume can then be successfully attached. Importing new key material into the existing KMS key (first incorrect option) would change the key material, making it unable to decrypt data encrypted with the original key material. Restoring from a snapshot (second incorrect option) might work if a recent snapshot exists, but it doesn't address the core issue of the unusable KMS key and might result in data loss if the snapshot is not current. Creating a new KMS key (fourth incorrect option) would also use different key material and would not be able to decrypt the existing EBS volume.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed