KMS Flashcards
When you enable automatic key rotation for a customer managed KMS key, how long it takes to the new cryptographic material to be rotated?
When you enable automatic key rotation for a KMS key, AWS KMS generates new cryptographic material for the KMS key every year.
How can you monitor the rotation of the key material or your KMS keys?
You can monitor rotation of the key material for your KMS keys in AWS CloudTrail and Amazon CloudWatch.
When you enable automatic key rotation for a AWS managed KMS key, how long it takes to the new cryptographic material to be rotated?
You cannot enable or disable automatic rotation AWS managed KMS keys. AWS KMS always rotates the key material of AWS managed keys every year.