Restore a deleted imported key material by reimporting the same material to decrypt the EBS volume

Answer Correct answer: C — reimport the same original key material to restore the key and decrypt the EBS volume; a snapshot is encrypted with the same key.

A company uses AWS Key Management Service (AWS KMS). During an attempt to attach an encrypted Amazon Elastic Block Store (Amazon EBS) volume to an Amazon EC2 instance, the attachment fails. The company discovers that a customer managed key has become unusable because the key material for the key was deleted. The company needs the data that is on the EBS volume. A security engineer must recommend a solution to decrypt the EBS volume’s encrypted data key. The solution must also attach the volume to the EC2 instance. Which solution will meet these requirements?

  1. Import new key material into the key. Attach the EBS volume.
  2. Restore the EBS volume from a snapshot that was taken before the deletion of the key material.
  3. Reimport the same key material that originally was imported into the key. Attach the EBS volume. Correct Answer
  4. Create a new key. Import new key material. Attach the EBS volume.

Community Votes

C
57%
B
43%

57% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

For a KMS key with imported key material, deleting the material is reversible—you can reimport the identical material to make the key usable again. The EBS volume's encrypted data key was wrapped by that exact key material, so only reimporting the same material restores decryption. Snapshots of the volume carry the same wrapping and would also be undecryptable while the key material is missing.

An EBS volume is encrypted with a customer managed KMS key whose imported key material was deleted, making the key unusable and blocking attachment. Because the EBS data key was encrypted with that specific key material, the only way to decrypt is to reimport the same original key material into the key (deleting imported material is reversible if you retained it). A snapshot of the volume is also encrypted with the same unusable key, so restoring from snapshot would not help.

Restoring from a snapshot (option B)—the snapshot is encrypted with the same now-unusable key, so it cannot be decrypted either. Or creating a new key with new material (option D)—new material cannot unwrap the existing data key.

Community Discussion (7 comments)

youonebe 👍 1 Selected: C
Answer is C. B is wrong because it wouldn't solve the problem as the snapshot would still be encrypted with the same unusable KMS key. C: Deleting the key material of a KMS key with imported key material is temporary and reversible. To restore the key, reimport its key material. https://docs.aws.amazon.com/kms/latest/developerguide/deleting-keys.html
TareDHakim 👍 1 Selected: B
tricky! B and C could work, BUT... there's no mention of available snapshots. so C is the better option.
Pmktechno 👍 1 Selected: B
This approach ensures that you can access the data using the snapshot, which retains the original encryption key material. Since the key material for the customer managed key was deleted, reimporting the same key material or creating a new key will not help in decrypting the existing data on the EBS volume.
IPLogic 👍 1 Selected: B
The correct solution to decrypt the EBS volume’s encrypted data key and attach the volume to the EC2 instance is: B. Restore the EBS volume from a snapshot that was taken before the deletion of the key material. When the key material for a customer managed key is deleted, the key becomes unusable, and you cannot decrypt data encrypted with that key. Therefore, the best approach is to restore the EBS volume from a snapshot taken before the key material was deleted. This ensures that the data can be decrypted using the key material that was valid at the time of the snapshot.
jdx000 👍 1 Selected: C
C is the only possible way to try to decrypt if the key material was not lost
723993f 👍 1 Selected: C
C] only way is to import the delete material if you still have it somewhere, B] does not wotk because snapshots are encrypted as well
DSExam 👍 1 Selected: C
The snapshot will be encrypted with the same key that was deleted so decryption of the snapshot will be impossible. Importing the same key material as the deleted key will restore the ability to decrypt the volume.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Deleting imported key material is reversible as long as you kept the original material; reimporting the same key material restores the key to a usable state, allowing KMS to decrypt the EBS volume's data key and attach the volume. This directly satisfies the requirement because the volume was encrypted with that specific material.

Why the Other Options Are Wrong

B is wrong because a snapshot of the volume is itself encrypted with the same unusable key, so restoring it would still fail to decrypt. D creates a new key with new material, which cannot unwrap the data key that was encrypted with the original material. A (import new material) also changes the material and cannot decrypt the existing data key.

Community Comment Notes

Community favored C (57 votes) over B (43). C supporters noted deleting imported material is temporary/reversible and reimporting the same material is the only way to decrypt; B fails because snapshots share the same unusable key. A minority argued B on the assumption a snapshot exists, but the scenario gives no such guarantee.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide