問題文
A team has to write a rotation policy for several keys with very different usage rates. Which basis does the documentation give, and what alternative covers the extreme case?
選択肢
- Estimate each key's encryption rate and rotate before the algorithm's published limit is reached; for very frequent needs use named keys tied to time windows.
- Rotate whenever the ciphertext count reported by the mount reaches the algorithm's limit, and for very frequent needs split the load across two mounts of the same engine.
- Rotate every key on the same monthly schedule, and for very frequent needs raise the number of versions the ring retains.
- Rotate only when the key's usage rate changes, and for very frequent needs disable the archive so the storage entry stays small.