How to Rotate Compromised MACsec Keys on AWS Direct Connect?

A network engineer is using AWS Direct Connect connections and MACsec to encrypt data from a corporate data center to the Direct Connect location. The network engineer learns that the MACsec secret key might have been compromised. The network engineer needs to update the connection with an uncompromised secure key. Which solution will meet this requirement?

  1. Create a new MACsec secret key that uses an AWS Key Management Service (AWS KMS) AWS managed key. Associate the new pre-shared key, Connection Key Name (CKN), and Connectivity Association Key (CAK) with the connection.
  2. Create a new MACsec secret key that uses an AWS Key Management Service (AWS KMS) customer managed key. Associate the new pre-shared key, Connection Key Name (CKN), and Connectivity Association Key (CAK) with the connection. Source Reference Answer
  3. Modify the existing MACsec secret key. Re-associate the existing pre-shared key, Connection Key Name (CKN), and Connectivity Association Key (CAK) with the connection.
  4. Modify the existing MACsec secret key. Associate the new pre-shared key, Connection Key Name (CKN), and Connectivity Association Key (CAK) with the connection.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests MACsec key lifecycle management on Direct Connect, where the common trap is attempting to modify an already-associated key instead of provisioning and linking a fresh one.

Rotating compromised MACsec keys on AWS Direct Connect requires creating a new secret key rather than modifying the existing one. Community consensus confirms that using a Customer Managed KMS key provides the necessary control for secure key replacement.

Options C and D: Candidates frequently select modification approaches because they assume secrets can be edited in place, but AWS explicitly blocks modifications to MACsec keys once bound to a connection or LAG.

Community Discussion (3 comments)

cas_tori 👍 1 Selected: B
this is B
veyisceylan 👍 1
MACsec pre-shared CKN/CAK key considerations AWS Direct Connect uses AWS managed CMKs for the pre-shared keys that you associate with connections or LAGs. Secrets Manager stores your pre-shared CKN and CAK pairs as a secret that the Secrets Manager’s root key encrypts. For more information, see AWS managed CMKs in the AWS Key Management Service Developer Guide.
KobDragoon 👍 4 Selected: B
You cannot modify a MACsec secret key after you associate it with a connection. If you need to modify the key, disassociate the key from the connection, and then associate a new key with the connection. https://docs.aws.amazon.com/directconnect/latest/UserGuide/associate-key-connection.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Creating a new MACsec secret key with a Customer Managed KMS key allows complete control over the encryption lifecycle, which is critical when a key is suspected of being compromised. AWS Direct Connect does not permit in-place modifications to MACsec keys after association; therefore, generating a fresh key pair and associating it with the connection is the only supported method. Using a customer managed key ensures you can independently rotate, disable, or delete the underlying KMS key without affecting the Direct Connect service.

Why the Other Options Are Wrong

Options C and D suggest modifying an existing MACsec secret key, which directly violates AWS limitations since associated keys are immutable. Option A proposes using an AWS managed key, which restricts your ability to manage key rotation policies and audit access independently, making it unsuitable for a compromised key scenario. All incorrect options fail to address the mandatory creation-and-reassociation workflow required by the platform.

Community Comment Notes

Comment [1] correctly highlights the core limitation: you cannot modify a MACsec secret key after association, requiring disassociation and reassociation of a new key. Comment [2] clarifies that while Direct Connect defaults to AWS managed CMKs for storage, opting for a customer managed CMK is recommended for enhanced security control during key rotation. Comment [3] simply corroborates the correct choice, reflecting strong alignment among test-takers.

Official Reference

Exam Strategy

Always remember that AWS networking resources like MACsec keys and VLANs are often immutable once attached; look for answers involving creation and reassociation rather than direct modification. Prioritize customer managed services over managed ones when the question involves security compromises or requires granular lifecycle control.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide