You manage encryption keys in AWS KMS and must ensure keys can be made unusable immediately when they are no longer required. The solution should be highly available and not require managing compute infrastructure. Which option satisfies these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Use customer-managed keys with imported key material. When a key is no longer needed, delete the imported key material..
Why this is the answer
The correct option, "Use customer-managed keys with imported key material. When a key is no longer needed, delete the imported key material," allows for immediate key invalidation. Deleting imported key material renders the KMS key unusable instantly, fulfilling the requirement for immediate action. This approach leverages KMS's high availability and managed infrastructure. "Use AWS-managed KMS keys, and when keys are no longer needed, schedule them for immediate deletion" is incorrect because AWS-managed keys cannot be deleted; they can only be disabled or have their key policy modified. "Use customer-managed keys, and when the key is no longer needed, delete the key material" is too general. While customer-managed keys are correct, the specific mechanism for immediate deletion is through imported key material. If the key material is generated by KMS, it can only be scheduled for deletion, not deleted immediately. "Use customer-managed keys backed by an AWS CloudHSM key store, and schedule the keys for immediate deletion when no longer needed" is incorrect because keys backed by CloudHSM can only be scheduled for deletion, not deleted immediately. While CloudHSM offers strong security, it doesn't provide immediate key deletion in the same way imported key material does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed