Use KMS with imported key material and DeleteImportedKeyMaterial for immediate key removal

Answer Correct answer: B — use KMS with imported key material and DeleteImportedKeyMaterial for immediate, scalable key removal.

A security engineer is implementing a solution to allow users to seamlessly encrypt Amazon S3 objects without having to touch the keys directly. The solution must be highly scalable without requiring continual management. Additionally, the organization must be able to immediately delete the encryption keys. Which solution meets these requirements?

  1. Use AWS KMS with AWS managed keys and the ScheduleKeyDeletion API with a PendingWindowInDays set to 0 to remove the keys if necessary.
  2. Use KMS with AWS imported key material and then use the DeleteImportedKeyMaterial API to remove the key material if necessary. Correct Answer
  3. Use AWS CloudHSM to store the keys and then use the CloudHSM API or the PKCS11 library to delete the keys if necessary.
  4. Use the Systems Manager Parameter Store to store the keys and then use the service API operations to delete the keys if necessary.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

With imported key material, KMS handles the service while you own the material; DeleteImportedKeyMaterial removes it at once, giving instant 'delete the keys.' AWS managed keys (A) do not support immediate deletion (ScheduleKeyDeletion has a minimum window). CloudHSM (C) requires you to manage HSMs, contradicting 'no continual management.' Parameter Store (D) stores parameters, not KMS keys. B is correct.

The team needs transparent S3 encryption at scale with no ongoing key management, plus the ability to instantly delete the key material. KMS with imported key material lets AWS manage the infrastructure while the company supplies and controls the key material; calling DeleteImportedKeyMaterial wipes the key material immediately (no waiting period), satisfying 'immediately delete.' AWS managed keys cannot be immediately deleted, CloudHSM needs HSM management, and Parameter Store is not a KMS key store.

Choosing AWS managed keys (A)—they cannot be deleted immediately; ScheduleKeyDeletion enforces a waiting period, failing the 'immediately delete' requirement. Choosing CloudHSM (C)—it meets control but requires direct HSM management, violating 'without continual management.' Using Parameter Store (D)—it stores configuration/secrets, not the KMS key material used for S3 encryption.

Community Discussion (3 comments)

723993f 👍 1 Selected: B
b but they should improve how the question is framed, is there anything as an AWS imported key material ?
gjurro 👍 1 Selected: B
A is incorrect because AWS KMS managed keys do not support immediate deletion. C is incorrect because AWS CloudHSM requires direct management of hardware security modules D is incorrect because AWS Systems Manager Parameter Store is not designed for encryption key management
mikelord 👍 4 Selected: B
B seems to be the right answer. Option A has no option to do immediate deletion

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

KMS with imported key material lets AWS operate the key infrastructure while the company controls and supplies the key material. Because the material is imported, DeleteImportedKeyMaterial removes it instantly with no pending window, meeting the 'immediately delete the encryption keys' requirement while keeping S3 encryption transparent and highly scalable.

Why the Other Options Are Wrong

A uses AWS managed keys, which cannot be deleted immediately—ScheduleKeyDeletion has a mandatory waiting period. C uses CloudHSM, which satisfies control but requires direct management of hardware security modules, contradicting 'without requiring continual management.' D uses Parameter Store, which stores parameters/secrets but is not the KMS key used to encrypt S3 objects. B is correct.

Community Comment Notes

Community voted B (100). Commenters noted AWS managed keys do not support immediate deletion and CloudHSM requires HSM management, whereas imported key material plus DeleteImportedKeyMaterial gives instant removal. B confirmed.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide