Bird
0
0

You want to ensure your KMS key automatically rotates every year and cannot be deleted accidentally. Which two settings should you configure?

hard📝 Best Practice Q15 of 15
AWS - Advanced Security
You want to ensure your KMS key automatically rotates every year and cannot be deleted accidentally. Which two settings should you configure?
ADisable key rotation and set a minimum 30-day deletion window
BEnable key rotation and set a minimum 7-day deletion window
CEnable key rotation and disable deletion window
DDisable key rotation and set deletion window to 0 days
Step-by-Step Solution
Solution:
  1. Step 1: Enable automatic yearly key rotation

    Enabling key rotation ensures the key updates automatically every year.
  2. Step 2: Set a deletion window to prevent accidental deletion

    A minimum 7-day deletion window is required to avoid immediate key loss and allow recovery.
  3. Final Answer:

    Enable key rotation and set a minimum 7-day deletion window -> Option B
  4. Quick Check:

    Rotation enabled + deletion window set = safe key management [OK]
Quick Trick: Rotate keys yearly and set deletion window ≥7 days [OK]
Common Mistakes:
  • Disabling rotation when it should be enabled
  • Setting deletion window to zero
  • Disabling deletion window entirely

Want More Practice?

15+ quiz questions · All difficulty levels · Free

Free Signup - Practice All Questions
More AWS Quizzes