AWS Certified Security - Specialty (#73)

An organization policy states that all encryption keys must be automatically rotated every 12 months. Which AWS Key Management Service (KMS) key type should be used to meet this requirement?

AWS managed Customer Master Key (CMK)
Customer managed CMK with AWS generated key material
Customer managed CMK with imported key material
AWS managed data key