[Incident Response]
A company is using an AWS Key Management Service (AWS KMS) AWS owned key in its application to encrypt files in an AWS account The company's security team wants the ability to change to new key material for new files whenever a potential key breach occurs A security engineer must implement a solution that gives the security team the ability to change the key whenever the team wants to do so
Which solution will meet these requirements?
To meet the requirement of changing the key material for new files whenever a potential key breach occurs, the most appropriate solution would be to create a new customer managed key, add a key rotation schedule to the key, and invoke the key rotation schedule every time the security team requests a key change.
References: :Rotating AWS KMS keys - AWS Key Management Service
Ula
4 days agoTiera
10 days agoLuz
15 days agoElza
21 days agoAnnmarie
26 days agoCortney
1 month agoKiley
1 month agoJacquelyne
2 months agoLinn
2 months agoEmilio
3 months agoLinn
3 months agoAimee
3 months agoJuan
2 months agoLorean
2 months agoWalton
2 months ago