A developer must migrate on-premises data to S3 using AWS KMS for encryption, and the encryption keys must support automatic annual rotation. Which type of KMS key should be used to satisfy these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Symmetric customer managed CMKs with key material generated by AWS.
Why this is the answer
Symmetric customer managed CMKs with key material generated by AWS are the correct choice because they support automatic annual key rotation, which is a requirement. These keys are managed by the customer within KMS, providing control while leveraging AWS's key generation and rotation services. Amazon S3-managed encryption keys (SSE-S3) do not allow the customer to manage the keys directly or control rotation schedules; AWS manages them entirely. Asymmetric customer managed CMKs are used for encryption and decryption or signing and verification, but not for encrypting data at rest in S3 with automatic rotation in the same way symmetric keys are. Symmetric customer managed CMKs with imported key material do not support automatic key rotation; rotation for imported key material must be performed manually by importing new key material.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed