nerdexam
Amazon

SCS-C02 · Question #277

A security engineer must use AWS Key Management Service (AWS KMS) to design a key management solution for a set of Amazon Elastic Block Store (Amazon EBS) volumes that contain sensitive data. The…

The correct answer is A. A customer managed CMK that uses customer provided key material. Go to AWS KMS console and try to configure AWS CMK with external key. The option to set expiration date is available at the end of last step where the key is uploaded to CMK.

Submitted by minji_kr· Mar 6, 2026Data Protection

Question

A security engineer must use AWS Key Management Service (AWS KMS) to design a key management solution for a set of Amazon Elastic Block Store (Amazon EBS) volumes that contain sensitive data. The solution needs to ensure that the key material automatically expires in 90 days. Which solution meets these criteria?

Options

  • AA customer managed CMK that uses customer provided key material
  • BA customer managed CMK that uses AWS provided key material
  • CAn AWS managed CMK
  • DOperating system-native encryption that uses GnuPG

How the community answered

(42 responses)
  • A
    74% (31)
  • B
    17% (7)
  • C
    2% (1)
  • D
    7% (3)

Explanation

Go to AWS KMS console and try to configure AWS CMK with external key. The option to set expiration date is available at the end of last step where the key is uploaded to CMK.

Topics

#AWS KMS#customer managed CMK#key material expiration#EBS encryption

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice