SAA-C03 Design Secure Architectures • Set 21
SAA-C03 Design Secure Architectures Practice Test 21 — 15 questions with explanations. Free, no signup.
In AWS Organizations, a Service Control Policy (SCP) denies kms:Decrypt on a production CMK for all principals in the Finance OU. A developer in the Finance OU created/updated an IAM policy that allows secrets access, but the application still fails with AccessDenied due to the SCP. You must enable only the Finance OU to decrypt that specific CMK while keeping the SCP restrictions for other OUs. What is the correct remediation?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.