nerdexam
Amazon

SCS-C02 · Question #110

A security engineer must use AWS Key Management Service (AWS KMS) to design a key management solution for a set of Amazon Elastic Block Store (Amazon EBS) volumes that contain sensitive data. The…

The correct answer is A. A customer managed key that uses customer provided key material. https://awscli.amazonaws.com/v2/documentation/api/latest/reference/kms/import-key-

Submitted by diego_uy· Mar 6, 2026Data Protection

Question

A security engineer must use AWS Key Management Service (AWS KMS) to design a key management solution for a set of Amazon Elastic Block Store (Amazon EBS) volumes that contain sensitive data. The solution needs to ensure that the key material automatically expires in 90 days. Which solution meets these criteria?

Options

  • AA customer managed key that uses customer provided key material
  • BA customer managed key that uses AWS provided key material
  • CAn AWS managed key
  • DOperating system encryption that uses GnuPG

How the community answered

(23 responses)
  • A
    78% (18)
  • B
    9% (2)
  • C
    9% (2)
  • D
    4% (1)

Explanation

https://awscli.amazonaws.com/v2/documentation/api/latest/reference/kms/import-key-

Topics

#KMS key material#customer managed key#key expiration#EBS encryption

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice