nerdexam
Amazon

SOA-C02 · Question #17

A SysOps Administrator is using AWS KMS with AWS-generated key material to encrypt an Amazon EBS volume in a company's AWS environment. The Administrator wants to rotate the KMS keys using automatic…

The correct answer is C. Enable automatic key rotation of the EBS volume key in AWS KMS. https://docs.aws.amazon.com/kms latest/developerguide/rotate-keys.html

Submitted by fernanda_arg· Mar 30, 2026Security and Compliance

Question

A SysOps Administrator is using AWS KMS with AWS-generated key material to encrypt an Amazon EBS volume in a company's AWS environment. The Administrator wants to rotate the KMS keys using automatic key rotation, and needs to ensure that the EBS volume encrypted with the current key remains readable. What should be done to accomplish this?

Options

  • ABack up the current KMS key and enable automatic key rotation.
  • BCreate a new key in AWS KMS and assign the key to Amazon EBS.
  • CEnable automatic key rotation of the EBS volume key in AWS KMS.
  • DUpload ne key material to the EBS volume key in AWS KMS to enable automatic key rotation for

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    75% (18)
  • D
    17% (4)

Explanation

https://docs.aws.amazon.com/kms latest/developerguide/rotate-keys.html

Topics

#KMS key rotation#EBS encryption#AWS-managed keys#automatic rotation

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice