How to Rotate Compromised MACsec Keys on AWS Direct Connect?
A network engineer is using AWS Direct Connect connections and MACsec to encrypt data from a corporate data center to the Direct Connect location. The network engineer learns that the MACsec secret key might have been compromised. The network engineer needs to update the connection with an uncompromised secure key. Which solution will meet this requirement?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests MACsec key lifecycle management on Direct Connect, where the common trap is attempting to modify an already-associated key instead of provisioning and linking a fresh one.
Rotating compromised MACsec keys on AWS Direct Connect requires creating a new secret key rather than modifying the existing one. Community consensus confirms that using a Customer Managed KMS key provides the necessary control for secure key replacement.
Options C and D: Candidates frequently select modification approaches because they assume secrets can be edited in place, but AWS explicitly blocks modifications to MACsec keys once bound to a connection or LAG.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Creating a new MACsec secret key with a Customer Managed KMS key allows complete control over the encryption lifecycle, which is critical when a key is suspected of being compromised. AWS Direct Connect does not permit in-place modifications to MACsec keys after association; therefore, generating a fresh key pair and associating it with the connection is the only supported method. Using a customer managed key ensures you can independently rotate, disable, or delete the underlying KMS key without affecting the Direct Connect service.Why the Other Options Are Wrong
Options C and D suggest modifying an existing MACsec secret key, which directly violates AWS limitations since associated keys are immutable. Option A proposes using an AWS managed key, which restricts your ability to manage key rotation policies and audit access independently, making it unsuitable for a compromised key scenario. All incorrect options fail to address the mandatory creation-and-reassociation workflow required by the platform.Community Comment Notes
Comment [1] correctly highlights the core limitation: you cannot modify a MACsec secret key after association, requiring disassociation and reassociation of a new key. Comment [2] clarifies that while Direct Connect defaults to AWS managed CMKs for storage, opting for a customer managed CMK is recommended for enhanced security control during key rotation. Comment [3] simply corroborates the correct choice, reflecting strong alignment among test-takers.Official Reference
Exam Strategy
Always remember that AWS networking resources like MACsec keys and VLANs are often immutable once attached; look for answers involving creation and reassociation rather than direct modification. Prioritize customer managed services over managed ones when the question involves security compromises or requires granular lifecycle control.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →