Use KMS with imported key material and DeleteImportedKeyMaterial for immediate key removal
A security engineer is implementing a solution to allow users to seamlessly encrypt Amazon S3 objects without having to touch the keys directly. The solution must be highly scalable without requiring continual management. Additionally, the organization must be able to immediately delete the encryption keys. Which solution meets these requirements?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
With imported key material, KMS handles the service while you own the material; DeleteImportedKeyMaterial removes it at once, giving instant 'delete the keys.' AWS managed keys (A) do not support immediate deletion (ScheduleKeyDeletion has a minimum window). CloudHSM (C) requires you to manage HSMs, contradicting 'no continual management.' Parameter Store (D) stores parameters, not KMS keys. B is correct.
The team needs transparent S3 encryption at scale with no ongoing key management, plus the ability to instantly delete the key material. KMS with imported key material lets AWS manage the infrastructure while the company supplies and controls the key material; calling DeleteImportedKeyMaterial wipes the key material immediately (no waiting period), satisfying 'immediately delete.' AWS managed keys cannot be immediately deleted, CloudHSM needs HSM management, and Parameter Store is not a KMS key store.
Choosing AWS managed keys (A)—they cannot be deleted immediately; ScheduleKeyDeletion enforces a waiting period, failing the 'immediately delete' requirement. Choosing CloudHSM (C)—it meets control but requires direct HSM management, violating 'without continual management.' Using Parameter Store (D)—it stores configuration/secrets, not the KMS key material used for S3 encryption.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.