SOA-C02 exam dumps

SOA-C02 practice question 206 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 206

Select 2

An organization uses AWS Key Management Service (KMS) to manage its encryption keys. The SysOps Administrator has been tasked with ensuring that the encryption keys are rotated automatically to meet compliance requirements. Additionally, they must ensure that access to these keys is limited to only specific IAM roles. What must the administrator do to fulfill these requirements?

  1. A

    Enable automatic key rotation for the Customer Managed Key (CMK) in AWS KMS.

  2. B

    Create a key policy that explicitly grants access to only specific IAM roles.

  3. C

    Use the AWS-managed keys instead of Customer Managed Keys (CMKs) to simplify the process.

  4. D

    Manually rotate the encryption keys every year to meet compliance requirements.

  5. E

    Ensure the key is set to the 'Enabled' state.

Show answer and explanation

Correct answers: A, B

Explanation

To meet the requirements, the administrator must enable automatic key rotation for the Customer Managed Key (CMK) in AWS KMS, which ensures compliance with annual key rotation policies. Additionally, a key policy should be created to restrict access to specific IAM roles, ensuring that only authorized entities can use the key. AWS-managed keys do not provide the flexibility required, and manual rotation is inefficient compared to the automated feature provided by KMS.

  • A. Correct.

    Enabling automatic key rotation for Customer Managed Keys (CMKs) in AWS KMS ensures that the key material is rotated automatically every year, meeting compliance requirements.

  • B. Correct.

    Creating a key policy that explicitly grants access to only specific IAM roles ensures that access to the encryption keys is restricted as per the organization's security policies.

  • C. Incorrect.

    AWS-managed keys do not allow you to customize key policies or enable automatic rotation; they are managed entirely by AWS and may not meet specific compliance requirements.

  • D. Incorrect.

    Manually rotating keys is not efficient and is unnecessary when automatic key rotation is available for Customer Managed Keys (CMKs).

  • E. Incorrect.

    While ensuring the key is 'Enabled' is required for it to be usable, this does not address the requirements of automatic key rotation or restricting access to specific IAM roles.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam