A network engineer uses AWS Direct Connect with MACsec to encrypt traffic between the data center and the Direct Connect location. The MACsec secret key may be compromised and must be replaced with a secure key. Which action meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new MACsec secret key that uses an AWS Key Management Service (AWS KMS) customer managed key. Associate the new pre-shared key, Connection Key Name (CKN), and Connectivity Association Key (CAK) with the connection..
Why this is the answer
When a MACsec secret key is compromised, it must be replaced entirely, not merely modified. AWS Direct Connect MACsec requires a new key to be generated. This new key should leverage an AWS Key Management Service (AWS KMS) customer managed key (CMK) for enhanced security and control over the key lifecycle. AWS managed keys are managed by AWS, offering less control. After generating the new key, the associated pre-shared key, Connection Key Name (CKN), and Connectivity Association Key (CAK) must all be updated and associated with the Direct Connect connection to establish secure communication with the new key. Modifying an existing key or re-associating old key components would not address the compromise.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed