SAA-C03 Design Secure Architectures • Set 5
SAA-C03 Design Secure Architectures Practice Test 5 — 15 questions with explanations. Free, no signup.
A service reads encrypted data from Amazon S3. The S3 objects use a customer-managed CMK. The IAM role used by the service has kms:Decrypt in its identity policy, but decryption fails with a KMS error stating the role is not authorized to perform kms:CreateGrant. The CMK’s key policy allows kms:Decrypt for the role but does not include kms:CreateGrant. What is the most appropriate change to resolve the failure while preserving least privilege?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.