HealthSync uses a symmetric customer managed KMS key with imported key material (origin EXTERNAL) to encrypt application data. A new compliance control mandates automatic annual rotation managed by AWS with minimal operational overhead. What is the best approach to meet this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new symmetric customer managed KMS key with AWS-generated key material, enable automatic rotation, and update applications to use a stable alias that points to the new key..
Why this is the answer
The correct option is to create a new symmetric customer managed KMS key with AWS-generated key material, enable automatic rotation, and update applications to use a stable alias that points to the new key. This is because KMS automatic key rotation is only supported for KMS keys with key material generated by AWS. Keys with imported key material (origin EXTERNAL) do not support AWS-managed automatic rotation. By creating a new key with AWS-generated material and using an alias, you achieve automatic rotation with minimal application changes, as the alias can be updated to point to the new key. Enabling automatic key rotation on the existing KMS key with imported key material will fail because KMS does not support automatic rotation for EXTERNAL origin keys. Configuring a yearly schedule to reimport new key material is a manual process and does not meet the requirement for automatic rotation managed by AWS with minimal operational overhead. Converting the existing key to an AWS managed key is not possible; a KMS key's origin (e.g., EXTERNAL) cannot be changed after creation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed