How should you detect Cloud KMS keys that are not rotated every 90 days?
You must ensure that the keys used for at-rest encryption of your data are compliant with your organization's security controls. One security control mandates that keys get rotated every 90 days. You must implement an effective detection strategy to validate if keys are rotated as required. What should you do?
Community Votes
70% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam asks whether you know the native SCC Security Health Analytics kms_key_not_rotated detector, not whether you can build a custom solution with Cloud Asset Inventory, Cloud Run, or Logging.
This page explains the correct detection strategy for verifying Cloud KMS key rotation against a 90-day security control on the PCSE exam. Security Health Analytics is the answer (D) because it automatically raises Security Command Center findings for keys older than 90 days.
Option A is tempting because Cloud Asset Inventory can expose key-version creation times, but it does not provide a managed 90-day rotation alert and is less effective than SCC Security Health Analytics.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Security Health Analytics, built into Security Command Center, includes the detector kms_key_not_rotated. If a Cloud KMS key has not been rotated in more than 90 days, this detector creates a finding in Security Command Center, which satisfies the detection strategy described in the question. This is the most direct, managed service approach because it is designed to assess the Google Cloud security posture and surfaces a clear remediation item. Google's SCC remediation guide confirms that this finding flags keys with no rotation in over 90 days.Why the Other Options Are Wrong
A analyzes crypto key versions via Cloud Asset Inventory and produces an alert, but it requires the customer to write and maintain custom logic and integration; Cloud Asset Inventory does not natively enforce or monitor 90-day rotation policy. B uses custom code in Cloud Run to raise findings, adding operational overhead and relying on the customer to build the detector. C suggests Cloud Logging metrics for timely key updates; rotation is not a simple log event, and checking for the absence of an update through logs is not an effective or supported detection method. Only D uses a purpose-built SCC service to generate a compliance finding.Community Comment Notes
As koo_kai and Pime13 pointed out, the official SCC remediation documentation contains the relevant kms_key_not_rotated finding, strongly supporting D. abdelrahman89 argued that Security Health Analytics is a specialized tool for assessing the environment's security posture and raising documented findings in SCC. A minority view, expressed by BPzen, favored Cloud Asset Inventory because key-version age data is visible, but this view requires custom monitoring rather than using Google Cloud's managed detector, which is the more appropriate exam answer.Official Reference
Exam Strategy
For detection questions on the PCSE exam, prefer built-in managed Security Health Analytics findings over custom infrastructure. Remember that the kms_key_not_rotated detector covers the 90-day rotation compliance check and produces SCC findings automatically.
Frequently Asked Questions
Why not use Cloud Asset Inventory to check key version age?
Cloud Asset Inventory can list CryptoKey versions and their create times, but it has no built-in rotation detector or alerting workflow; Security Health Analytics is the managed service for this.
Does Security Health Analytics automatically check the 90-day rotation policy?
Yes, its kms_key_not_rotated detector identifies Cloud KMS keys that were not rotated within the required period and raises an SCC finding for remediation.