A security engineer must design an AWS Key Management Service (AWS KMS) solution for Amazon EBS volumes that contain sensitive data. The key material must automatically expire after 90 days. Which option meets this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: A customer managed key that uses customer-provided (imported) key material.
Why this is the answer
Customer-managed keys with imported key material allow you to bring your own key material into AWS KMS. This option provides the flexibility to define the key material's lifecycle, including setting an expiration date. You can import key material that is configured to expire after 90 days, meeting the requirement. AWS-provided key material for customer-managed keys, and AWS managed keys, do not allow you to set an expiration date for the key material; AWS manages their lifecycle. Operating system encryption using GnuPG is not an AWS KMS solution and would not integrate with EBS encryption in the way specified.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed