Full AWS Practitioner Certification Question

A company is planning to store highly sensitive data in Amazon S3. Compliance mandates require that the data be encrypted at rest, that all encryption key usage be auditable, and that encryption keys be rotated automatically every year. The company wants to minimize the operational overhead of managing this process.Which encryption approach best satisfies these requirements?