[Incident Response]
A company is using an AWS Key Management Service (AWS KMS) AWS owned key in its application to encrypt files in an AWS account The company's security team wants the ability to change to new key material for new files whenever a potential key breach occurs A security engineer must implement a solution that gives the security team the ability to change the key whenever the team wants to do so
Which solution will meet these requirements?
To meet the requirement of changing the key material for new files whenever a potential key breach occurs, the most appropriate solution would be to create a new customer managed key, add a key rotation schedule to the key, and invoke the key rotation schedule every time the security team requests a key change.
References: :Rotating AWS KMS keys - AWS Key Management Service
Mireya
2 months agoKeneth
2 months agoMarsha
3 months agoTonette
3 months agoVesta
4 months agoLanie
4 months agoUla
4 months agoTiera
4 months agoLuz
5 months agoElza
5 months agoAnnmarie
5 months agoCortney
5 months agoKiley
5 months agoJacquelyne
6 months agoGayla
3 months agoKip
3 months agoMarilynn
3 months agoCammy
4 months agoLinn
6 months agoEmilio
7 months agoLinn
7 months agoAimee
7 months agoJuan
6 months agoLorean
6 months agoWalton
6 months ago