Amazon
SCS-C02 · Question #110
A security engineer must use AWS Key Management Service (AWS KMS) to design a key management solution for a set of Amazon Elastic Block Store (Amazon EBS) volumes that contain sensitive data. The…
The correct answer is A. A customer managed key that uses customer provided key material. https://awscli.amazonaws.com/v2/documentation/api/latest/reference/kms/import-key-
Submitted by diego_uy· Mar 6, 2026Data Protection
Question
A security engineer must use AWS Key Management Service (AWS KMS) to design a key management solution for a set of Amazon Elastic Block Store (Amazon EBS) volumes that contain sensitive data. The solution needs to ensure that the key material automatically expires in 90 days. Which solution meets these criteria?
Options
- AA customer managed key that uses customer provided key material
- BA customer managed key that uses AWS provided key material
- CAn AWS managed key
- DOperating system encryption that uses GnuPG
How the community answered
(23 responses)- A78% (18)
- B9% (2)
- C9% (2)
- D4% (1)
Explanation
https://awscli.amazonaws.com/v2/documentation/api/latest/reference/kms/import-key-
Topics
#KMS key material#customer managed key#key expiration#EBS encryption
Community Discussion
No community discussion yet for this question.