The customer-managed key that protects lock-lab SQL TDE has never rotated. What should the security engineer configure in Key Vault?
Select an answer to reveal the explanation.
Short Explanation
Stop relying on a sticky note to the DBA. Put a rotation policy on the CMK so Key Vault mints a new version on the schedule—before expiry, not after an outage.
Full Explanation
Key Vault supports rotation policies on keys so new versions are created automatically based on time or expiry-related settings. That is the native control for CMK lifecycle used by services such as SQL TDE with customer-managed keys. Manual email reminders are not an Azure control. Disabling TDE or deleting keys without versioned rotation increases risk rather than managing it.