Use a KMS key alias and create a new customer managed key on each change
A company is using an AWS Key Management Service (AWS KMS) AWS owned key in its application to encrypt files in an AWS account. The company's security team wants the ability to change to new key material for new files whenever a potential key breach occurs. A security engineer must implement a solution that gives the security team the ability to change the key whenever the team wants to do so. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A key alias decouples the application reference from the underlying key; swapping the alias to a freshly created CMK changes the material used for new files without touching application configuration. AWS managed keys (B/D) are created/maintained by AWS and you cannot freely create new ones on demand; CMK rotation (A) is scheduled/automatic and not an on-demand breach response. C is the control the customer wants.
With an AWS-owned key the company cannot control key material; to allow on-demand key changes, create a customer managed key (CMK) and reference it through a key alias. On each suspected breach, create a new CMK and repoint the alias to it—applications keep using the alias, so no code change is needed and new files use the new material. AWS managed keys cannot be created on demand by the customer the same way, and alias+CMK gives full lifecycle control.
Choosing A's scheduled key rotation—KMS automatic rotation keeps the same key ID and only rotates backing material on a schedule; it is not an on-demand 'change whenever we want' control. Choosing AWS managed keys (B/D)—the customer cannot create new AWS managed keys at will, defeating the requirement.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.