AnswerCorrect answer: D — create a new CMK, import new key material, and repoint the alias; auto-rotation is unavailable for imported-key keys.
A company has an AWS Key Management Service (AWS KMS) customer managed key with imported key material. Company policy requires all encryption keys to be rotated every year. What should a security engineer do to meet this requirement for this customer managed key?
Enable automatic key rotation annually for the existing customer managed key.
Use the AWS CLI to create an AWS Lambda function to rotate the existing customer managed key annually.
Import new key material to the existing customer managed key. Manually rotate the key.
Create a new customer managed key. Import new key material to the new key. Point the key alias to the new key. Correct Answer
Community Votes
D
100%
100% of anonymous learners picked answer D.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Automatic rotation is unavailable for imported-key KMS keys, and an imported-key KMS key is bound to the key material first imported (you can only reimport the same material). True rotation requires new key material, which means a new key; repointing the alias keeps application references stable while satisfying the annual-rotation policy.
A customer managed KMS key uses imported key material, and policy requires annual rotation. AWS KMS does not support automatic key rotation for keys with imported key material, and you cannot import different key material into an existing imported-key KMS key. The rotation path is to create a new customer managed key, import fresh key material into it, and point the existing key alias to the new key so callers transparently use the rotated key.
Enabling automatic rotation (option A)—not supported for imported key material. Or reimporting the same material to the existing key (option C)—that restores rather than rotates and does not satisfy a rotation-to-new-material policy.
Community Discussion (7 comments)
m_ch333👍 1Selected: D
D. - you cannot enable automatic key rotation for a KMS key with imported key material - You can reimport the same key material, but you cannot import different key material into that KMS key https://docs.aws.amazon.com/kms/latest/developerguide/importing-keys-considerations.html
IPLogic👍 1Selected: D
The correct approach to meet the requirement of rotating the encryption key annually for a customer managed key with imported key material is: D. Create a new customer managed key. Import new key material to the new key. Point the key alias to the new key. Automatic key rotation is not supported for keys with imported key material. Therefore, you need to manually manage the rotation by creating a new key and updating the alias to point to the new key each year.
723993f👍 1Selected: C
c is the answer, d is unnecessary work kms cmk = metadata (id, other field) + imported material (crypto) thus kms cmk can continue to be as is with the same id, and we can import new material to it why not d - there is no mention of an alias being used, and no its not obvious, one must mention that an alias was created and being used by apps for D to be a viable solution
dhewa👍 1Selected: D
To comply with the policy of rotating encryption keys annually, the recommended approach is to create a new customer managed key, import new key material to this new key, and then update the key alias to point to the new key. This ensures that the key rotation is handled correctly and securely.
imymoco👍 1
Why not C? I think C is correct. D is viable, but it hasmore operational overhead
gkaself👍 2Selected: D
Correct answer is D
mikelord👍 2Selected: D
Option D make more sense
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
KMS automatic key rotation cannot be enabled on a key with imported key material, and an imported-key KMS key cannot accept different key material once created. To rotate, you create a new customer managed key, import new key material, and update the alias to point at the new key, so applications referencing the alias transparently use rotated material and the annual policy is met.
Why the Other Options Are Wrong
A is wrong because automatic rotation is unsupported for imported key material. B is wrong because Lambda cannot rotate an imported-key KMS key's material—the material is externally sourced. C reimports the same material to the existing key, which is restoration, not rotation, and does not provide new key material as the policy requires.
Community Comment Notes
Community favored D (88 votes). A commenter cited the imported-keys doc: you cannot enable auto rotation and cannot import different material into an existing imported-key KMS key. A minority argued C, but C reuses the same material and is not a rotation.