SecurityDevOps/Cloud

Key Rotation

Also written as Credential Rotation, Key Management, Certificate Rotation

Replacing encryption keys, API credentials and certificates on a schedule, so a leaked secret is only useful for a limited window.

Think of it like

Changing the locks periodically, so a copied key stops working whether or not you ever learn it was copied.

Junior or senior?

Easy to claim, genuinely painful to do.

Senior sounds like

Has rotated a credential half the estate depended on and can describe how they avoided an outage.

Ask them

“Tell me about rotating a credential that many systems depended on. How did you avoid taking them down?”