Key rotation replaces the cryptographic material behind a KMS key on a schedule, limiting how much data is protected by any single key version — a common compliance requirement.
Automatic vs manual
For customer-managed keys, KMS can automatically rotate the key material once a year (older versions are retained so old data still decrypts). You can also manually rotate by creating a new key and re-pointing an alias. AWS-managed keys rotate automatically. The tell is “meet a policy that requires periodic key rotation.”
Test yourself
A compliance rule requires encryption keys to be rotated regularly with minimal operational effort. For a customer-managed KMS key, what’s the simplest approach?
- Delete and recreate the key each year
- Enable automatic key rotation on the KMS key
- Store keys in S3 and swap them
- Turn off encryption periodically
👉 Click to reveal the answer & explanation
Correct answer: B. Enabling automatic rotation on a customer-managed KMS key rotates the material yearly while retaining old versions for decryption — minimal effort. Deleting/recreating (A) breaks decryption of old data; storing keys in S3 (C) and disabling encryption (D) are insecure.
Related topics
AWS KMS · S3 encryption · AWS Secrets Manager
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first