SCS-C02 · Question #473
A company must create annual snapshots of Amazon Elastic Block Store (Amazon EBS) volumes. The company must retain the snapshots for 10 years. The company will use AWS Key Management Service (AWS…
The correct answer is B. Symmetric customer managed KMS keys with key material created by AWS KMS. For EBS volume encryption with AWS KMS, symmetric customer managed KMS keys are recommended because they support automatic key rotation and are compatible with EBS volume and snapshot encryption. AWS KMS automatically manages previous key versions, ensuring that snapshots…
Question
A company must create annual snapshots of Amazon Elastic Block Store (Amazon EBS) volumes. The company must retain the snapshots for 10 years. The company will use AWS Key Management Service (AWS KMS) to encrypt the EBS volumes and snapshots. The encryption keys must be rotated automatically every year. Snapshots that were created in previous years must be readable after rotation of the encryption keys. Which type of KMS keys should the company use for encryption to meet these requirements?
Options
- AAsymmetric AWS managed KMS keys with key material created by AWS KMS
- BSymmetric customer managed KMS keys with key material created by AWS KMS
- CSymmetric customer managed KMS keys with custom imported key material
- DAsymmetric AWS managed KMS keys with custom imported key material
How the community answered
(28 responses)- A4% (1)
- B82% (23)
- C7% (2)
- D7% (2)
Explanation
For EBS volume encryption with AWS KMS, symmetric customer managed KMS keys are recommended because they support automatic key rotation and are compatible with EBS volume and snapshot encryption. AWS KMS automatically manages previous key versions, ensuring that snapshots created with older key versions remain readable even after key rotation. This meets the requirement for automatic annual rotation and backward compatibility for reading older
Topics
Community Discussion
No community discussion yet for this question.