How should you detect Cloud KMS keys that are not rotated every 90 days?

Cloud Security – Key Management and Security Command Center
Answer Correct answer: D — Use Security Health Analytics to identify Cloud KMS keys not rotated within 90 days and create SCC findings.

You must ensure that the keys used for at-rest encryption of your data are compliant with your organization's security controls. One security control mandates that keys get rotated every 90 days. You must implement an effective detection strategy to validate if keys are rotated as required. What should you do?

  1. Analyze the crypto key versions of the keys by using data from Cloud Asset Inventory. If an active key is older than 90 days, send an alert message through your incident notification channel.
  2. Assess the keys in the Cloud Key Management Service by implementing code in Cloud Run. If a key is not rotated after 90 days, raise a finding in Security Command Center.
  3. Define a metric that checks for timely key updates by using Cloud Logging. If a key is not rotated after 90 days, send an alert message through your incident notification channel.
  4. Identify keys that have not been rotated by using Security Health Analytics. If a key is not rotated after 90 days, a finding in Security Command Center is raised. Correct Answer

Community Votes

D
70%
A
30%

70% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam asks whether you know the native SCC Security Health Analytics kms_key_not_rotated detector, not whether you can build a custom solution with Cloud Asset Inventory, Cloud Run, or Logging.

This page explains the correct detection strategy for verifying Cloud KMS key rotation against a 90-day security control on the PCSE exam. Security Health Analytics is the answer (D) because it automatically raises Security Command Center findings for keys older than 90 days.

Option A is tempting because Cloud Asset Inventory can expose key-version creation times, but it does not provide a managed 90-day rotation alert and is less effective than SCC Security Health Analytics.

Community Discussion (7 comments)

Pime13 👍 1 Selected: D
https://cloud.google.com/security-command-center/docs/how-to-remediate-security-health-analytics-findings#kms_key_not_rotated
BPzen 👍 1 Selected: A
Why A is Correct: Cloud Asset Inventory: Cloud Asset Inventory offers a detailed view of cryptographic keys, including the age of each key version. By periodically analyzing this data, you can determine if a key version has been in use for more than 90 days. Proactive Monitoring: This approach allows you to set up automated checks and send alerts to incident notification channels (e.g., email, Slack, PagerDuty) when keys exceed the allowed age.
MoAk 👍 2 Selected: D
D - https://cloud.google.com/security-command-center/docs/how-to-remediate-security-health-analytics-findings#kms_key_not_rotated
jmaquino 👍 1 Selected: A
https://cloud.google.com/secret-manager/docs/analyze-resources?hl=es-419
koo_kai 👍 4 Selected: D
It's D https://cloud.google.com/security-command-center/docs/how-to-remediate-security-health-analytics-findings#kms_key_not_rotated
siheom 👍 1 Selected: A
VOTE A
abdelrahman89 👍 4
D - Security Health Analytics: Security Health Analytics is a specialized tool designed to assess the security posture of your Google Cloud environment. It can effectively identify keys that have not been rotated within the specified timeframe. Finding in Security Command Center: Raising a finding in Security Command Center ensures that the non-compliance issue is clearly documented and can be addressed promptly. Efficiency: Security Health Analytics provides a streamlined and efficient way to monitor key rotation compliance without requiring custom code or manual analysis.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Security Health Analytics, built into Security Command Center, includes the detector kms_key_not_rotated. If a Cloud KMS key has not been rotated in more than 90 days, this detector creates a finding in Security Command Center, which satisfies the detection strategy described in the question. This is the most direct, managed service approach because it is designed to assess the Google Cloud security posture and surfaces a clear remediation item. Google's SCC remediation guide confirms that this finding flags keys with no rotation in over 90 days.

Why the Other Options Are Wrong

A analyzes crypto key versions via Cloud Asset Inventory and produces an alert, but it requires the customer to write and maintain custom logic and integration; Cloud Asset Inventory does not natively enforce or monitor 90-day rotation policy. B uses custom code in Cloud Run to raise findings, adding operational overhead and relying on the customer to build the detector. C suggests Cloud Logging metrics for timely key updates; rotation is not a simple log event, and checking for the absence of an update through logs is not an effective or supported detection method. Only D uses a purpose-built SCC service to generate a compliance finding.

Community Comment Notes

As koo_kai and Pime13 pointed out, the official SCC remediation documentation contains the relevant kms_key_not_rotated finding, strongly supporting D. abdelrahman89 argued that Security Health Analytics is a specialized tool for assessing the environment's security posture and raising documented findings in SCC. A minority view, expressed by BPzen, favored Cloud Asset Inventory because key-version age data is visible, but this view requires custom monitoring rather than using Google Cloud's managed detector, which is the more appropriate exam answer.

Official Reference

Exam Strategy

For detection questions on the PCSE exam, prefer built-in managed Security Health Analytics findings over custom infrastructure. Remember that the kms_key_not_rotated detector covers the 90-day rotation compliance check and produces SCC findings automatically.

Frequently Asked Questions

Why not use Cloud Asset Inventory to check key version age?

Cloud Asset Inventory can list CryptoKey versions and their create times, but it has no built-in rotation detector or alerting workflow; Security Health Analytics is the managed service for this.

Does Security Health Analytics automatically check the 90-day rotation policy?

Yes, its kms_key_not_rotated detector identifies Cloud KMS keys that were not rotated within the required period and raises an SCC finding for remediation.

Related Analysis

← Back to PCSE Study Guide