Home/Exams/AWS KMS
Real Exam ScenarioAWS KMS

You are designing a solution for an audit firm that needs to store encrypted data in S3 for 10 years. They require that the encryption keys are rotated annually and that no one, including AWS, can access the cleartext keys. Which AWS KMS key type and rotation should you use?