Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 25 Topic 3 Discussion

Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 25 Topic 3 Discussion

SAA-C03 Exam Topic 3 Question 25 Discussion:
Question #: 25
Topic #: 3

A company must follow strict regulations for the management of data encryption keys. The company manages its own key externally and imports the key into AWS Key Management Service (AWS KMS). The company must control the imported key material and must rotate the key material on a regular schedule.

A solutions architect needs to import the key material into AWS KMS and rotate the key without interrupting applications that use the key.

Which solution will meet these requirements?


A.

Create a new AWS KMS key that has the same key ID as the existing key. Import new key material into the key.


B.

Schedule the existing AWS KMS key for deletion. Create a new KMS key that has new key material.


C.

Import new key material into the existing AWS KMS key. Set an expiration time for the old key material.


D.

Enable automatic key rotation for the existing AWS KMS key.


Get Premium SAA-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.