nerdexam
Amazon

SOA-C03 · Question #143

A company has a new security policy that requires all Amazon Elastic Block Store (Amazon EBS) volumes to be encrypted at rest. The company needs to use a custom key policy to manage access to the…

The correct answer is A. Create AWS KMS symmetric customer managed keys. Enable automatic key rotation. AWS KMS symmetric customer managed keys with automatic key rotation provide encryption, access control, and compliance with minimal operational effort. AWS CloudOps documentation states that Amazon EBS encryption supports AWS KMS symmetric keys only, and customer managed keys…

Submitted by jakub_pl· Mar 5, 2026Security and compliance

Question

A company has a new security policy that requires all Amazon Elastic Block Store (Amazon EBS) volumes to be encrypted at rest. The company needs to use a custom key policy to manage access to the encryption keys. The company must rotate the keys once each year. Which solution will meet these requirements with the LEAST operational overhead?

Options

  • ACreate AWS KMS symmetric customer managed keys. Enable automatic key rotation.
  • BUse AWS owned AWS KMS keys across the company's AWS environment.
  • CCreate AWS KMS asymmetric customer managed keys. Enable automatic key rotation.
  • DCreate AWS KMS symmetric customer managed keys by using imported key material. Rotate the

How the community answered

(43 responses)
  • A
    84% (36)
  • B
    9% (4)
  • C
    2% (1)
  • D
    5% (2)

Explanation

AWS KMS symmetric customer managed keys with automatic key rotation provide encryption, access control, and compliance with minimal operational effort. AWS CloudOps documentation states that Amazon EBS encryption supports AWS KMS symmetric keys only, and customer managed keys allow administrators to define custom key policies to control access. Automatic key rotation is supported for symmetric customer managed keys and rotates the backing key material once every year, fully satisfying the company's rotation requirement without manual intervention. This approach minimizes operational overhead while maintaining strong security controls and auditability.

Topics

#KMS#EBS encryption#key rotation#customer managed keys

Community Discussion

No community discussion yet for this question.

Full SOA-C03 Practice