Key rotation replaces the cryptographic material behind a KMS key on a schedule, limiting how much data is protected by any single key version — a common compliance requirement.

Automatic vs manual

For customer-managed keys, KMS can automatically rotate the key material once a year (older versions are retained so old data still decrypts). You can also manually rotate by creating a new key and re-pointing an alias. AWS-managed keys rotate automatically. The tell is “meet a policy that requires periodic key rotation.”

Test yourself

Practice question

A compliance rule requires encryption keys to be rotated regularly with minimal operational effort. For a customer-managed KMS key, what’s the simplest approach?

  1. Delete and recreate the key each year
  2. Enable automatic key rotation on the KMS key
  3. Store keys in S3 and swap them
  4. Turn off encryption periodically
👉 Click to reveal the answer & explanation

Correct answer: B. Enabling automatic rotation on a customer-managed KMS key rotates the material yearly while retaining old versions for decryption — minimal effort. Deleting/recreating (A) breaks decryption of old data; storing keys in S3 (C) and disabling encryption (D) are insecure.

Related topics

AWS KMS · S3 encryption · AWS Secrets Manager

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access