KMS Flashcards

1
Q

When you enable automatic key rotation for a customer managed KMS key, how long it takes to the new cryptographic material to be rotated?

A

When you enable automatic key rotation for a KMS key, AWS KMS generates new cryptographic material for the KMS key every year.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How can you monitor the rotation of the key material or your KMS keys?

A

You can monitor rotation of the key material for your KMS keys in AWS CloudTrail and Amazon CloudWatch.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When you enable automatic key rotation for a AWS managed KMS key, how long it takes to the new cryptographic material to be rotated?

A

You cannot enable or disable automatic rotation AWS managed KMS keys. AWS KMS always rotates the key material of AWS managed keys every year.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly