ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 249 - SCS-C01 discussion

Report
Export

When you enable automatic key rotation for an existing CMK key where the backing key is managed by AWS, after how long is the key rotated? Please select:

A.
After 30 days
Answers
A.
After 30 days
B.
After 128 days
Answers
B.
After 128 days
C.
After 365 days
Answers
C.
After 365 days
D.
After 3 years
Answers
D.
After 3 years
Suggested answer: D

Explanation:

The AWS Documentation states the following

• AWS managed CM Ks: You cannot manage key rotation for AWS managed CMKs. AWS KMS automatically rotates AWS managed keys every three years (1095 days). Note: AWS-managed CMKs are rotated every 3yrs, Customer-Managed CMKs are rotated every 365- days from when rotation is enabled. Option A, B, C are invalid because the dettings for automatic key rotation is not changeable.

For more information on key rotation please visit the below URL

https://docs.aws.amazon.com/kms/latest/developereuide/rotate-keys.htmlAWS managed CMKs are CMKs in your account that are created, managed, and used on your behalfby an AWS service that is integrated with AWS KMS. This CMK is unique to your AWS account andregion. Only the service that created the AWS managed CMK can use itYou can login to you IAM dashbaord . Click on "Encryption Keys"You will find the list based on the services you are using as follows:

• aws/elasticfilesystem 1 aws/lightsail

• aws/s3

• aws/rds and many more

Detailed Guide: KMS

You can recognize AWS managed CMKs because their aliases have the format aws/service-name, such as aws/redshift. Typically, a service creates its AWS managed CMK in your account when you set up the service or the first time you use the CMfC The AWS services that integrate with AWS KMS can use it in many different ways. Some services create AWS managed CMKs in your account. Other services require that you specify a customer managed CMK that you have created. And, others support both types of CMKs to allow you the ease of an AWS managed CMK or the control of a customer-managed CMK Rotation period for CMKs is as follows:

• AWS managed CMKs: 1095 days

• Customer managed CMKs: 365 days

Since question mentions about "CMK where backing keys is managed by AWS", its Amazon(AWS) managed and its rotation period turns out to be 1095 days{every 3 years) For more details, please check below AWS Docs:

https://docs.aws.amazon.com/kms/latest/developerguide/concepts.htmlThe correct answer is: After 3 yearsSubmit your Feedback/Queries to our Experts

asked 16/09/2024
Andrea Ciovati
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first