โ† All AWS Flashcard Decks

Certified Solutions Architect Data Encryption with KMS Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Certified Solutions Architect Data Encryption with KMS flashcards as text
  1. A company operates in multiple AWS Regions and needs the same KMS key material available in all regions for consistent encryption. What is the correct AWS KMS feature to use?

    Answer: Use KMS multi-Region keys

    KMS multi-Region keys are a set of interoperable keys with identical key material and key IDs that can be used independently in multiple AWS Regions.

  2. An EBS volume is encrypted with KMS key A. A snapshot is taken and shared with another AWS account. What must be done so the other account can create an encrypted volume from the snapshot?

    Answer: Grant the other account kms:DescribeKey and kms:CreateGrant on key A, or re-encrypt the snapshot with a key the other account owns

    Cross-account snapshot sharing requires that the receiving account has KMS key permissions to use the source key, or the snapshot must be re-encrypted with a key the receiving account controls.

  3. Which KMS key rotation policy is automatically applied to AWS managed keys (e.g., aws/s3)?

    Answer: Annual automatic rotation every 365 days

    AWS managed keys rotate automatically every year (365 days), and this behavior cannot be disabled by customers.

  4. A developer calls kms:GenerateDataKeyWithoutPlaintext. What does this API return compared to kms:GenerateDataKey?

    Answer: Only the encrypted data key, without the plaintext version

    GenerateDataKeyWithoutPlaintext returns only the encrypted data key, which is useful when you want to store the encrypted key for later decryption without ever exposing the plaintext.

  5. A KMS key policy does not explicitly allow the AWS account root user. What is the effect on IAM policies for that key?

    Answer: IAM policies have no effect; only the key policy controls access

    If the key policy does not grant the account root access, IAM policies cannot override the key policy, potentially locking everyone out of the key.

  6. A company wants to use AWS CloudTrail to audit every use of a KMS key. Which CloudTrail event source should they monitor?

    Answer: kms.amazonaws.com

    All KMS API calls, including Encrypt, Decrypt, and GenerateDataKey, are logged by CloudTrail under the kms.amazonaws.com event source.

  7. What is the minimum waiting period before AWS permanently deletes a KMS key after scheduling its deletion?

    Answer: 7 days

    The minimum key deletion waiting period is 7 days (default is 30 days), during which you can cancel the deletion if the key is still needed.