key rotation/revocation

Let us say I am using KMS with AWS managed keys, and the key is rotated. 

So my question is

1. Can the encryption key be compromised by an attacker?

2. If the key can be and is compromised, what shall I do to protect the confidentiality of data while ensuring the authorized party continues to have access to the data?

