A Compliance Auditor is validating that a VCF Workload Domain meets the "Continuous Key Rotation" requirements of a strict financial standard (e.g., SOX/PCI).
The auditor examines the vCenter logs surrounding the Data-in-Transit (DiT) configuration.
```
[Log Analysis: vpxd.log]
2026-11-20T12:00:00Z INFO vpxd - [DiT] Rekey interval expired (1440 minutes).
2026-11-20T12:00:01Z INFO vpxd - [DiT] Ephemeral session keys successfully renegotiated between
[esx-03] and [esx-05].
2026-11-20T12:00:02Z INFO vpxd - [DiT] Old key buffer purged.
```
How does the DiT key rotation architecture satisfy compliance without relying on external KMS administrators? (Select all that apply.)