Courseiva
Data Security and GovernancehardMultiple SelectObjective-mapped

DEA-C01 Data Security and Governance Practice Question

A company uses AWS KMS to encrypt data in multiple services. They want to ensure that only specific IAM roles can decrypt data using a particular KMS key. Which TWO steps are necessary?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Attach an IAM policy to each role with kms:Decrypt permission

To allow specific IAM roles to decrypt data using a KMS key, two steps are required. First, each role must have an IAM policy that grants the kms:Decrypt permission (A). Second, the KMS key policy must include a statement that allows the IAM roles to perform kms:Decrypt (E). The permission kms:GenerateDataKey (D) is not needed for decryption-only access; it is used for generating data keys during encryption. Options B (enabling IAM policies in key policy) and C (automatic key rotation) are unrelated to access control for decryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Attach an IAM policy to each role with kms:Decrypt permission

    Why this is correct

    Correct. The IAM policy attached to the role must include kms:Decrypt to allow the role to decrypt using the key.

  • Enable IAM policies in the key policy

    Why it's wrong here

    Incorrect. Enabling IAM policies in the key policy is not a required step; the key policy itself must allow the IAM roles, but IAM policies are separate.

  • Enable automatic key rotation

    Why it's wrong here

    Incorrect. Automatic key rotation is a security best practice but not required for controlling decrypt access.

  • Ensure the key policy allows kms:GenerateDataKey for the roles

    Why it's wrong here

    Incorrect. kms:GenerateDataKey is used for encryption, not decryption. Therefore, it is not necessary for roles that only need to decrypt data.

  • Add a statement to the KMS key policy allowing kms:Decrypt for the IAM roles

    Why this is correct

    Correct. The KMS key policy must explicitly allow the IAM roles to perform kms:Decrypt. This is necessary because KMS key policies act as a resource-based policy that controls access to the key.

About these practice questions

This DEA-C01 question is part of Courseiva's 1,711-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.