DEA-C01 Data Security and Governance Practice Question
A data engineer is troubleshooting an ETL job that reads from an S3 bucket encrypted with SSE-KMS. The job is failing with an error indicating that the IAM role does not have permission to decrypt the data. What is the most likely missing permission?
⚠ Common exam trap
The trap is assuming that s3:GetObject alone is sufficient to read SSE-KMS encrypted objects, ignoring the separate KMS permission required for decryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
kms:Decrypt
When an S3 object is encrypted with SSE-KMS, reading the object requires two sets of permissions: s3:GetObject on the object and kms:Decrypt on the KMS key used to encrypt it. The error explicitly states the IAM role lacks permission to decrypt, so the missing permission is kms:Decrypt. Without it, S3 cannot call KMS to decrypt the data key, and the GetObject call fails with AccessDenied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kms:GenerateDataKey
Why it's wrong here
kms:GenerateDataKey is needed for uploads to produce a data key, not for reading; decryption requires kms:Decrypt. It is tempting because both permissions appear in SSE-KMS policies, and GenerateDataKey would be the missing grant if the job were writing encrypted objects instead of reading them.
- ✗
s3:ListBucket
Why it's wrong here
s3:ListBucket governs listing objects in a bucket, not decrypting object data, so it cannot resolve a KMS decryption failure. It is tempting because ListBucket errors often surface during ETL job setup, and it would be the correct missing permission if the job failed to enumerate bucket contents.
- ✓
kms:Decrypt
Why this is correct
SSE-KMS requires the caller to hold kms:Decrypt on the customer-managed key before S3 can return the object. The role's S3 permissions are irrelevant here; the missing KMS grant is what blocks the ETL job's reads.
- ✗
s3:GetObject
Why it's wrong here
s3:GetObject grants read access to the object but does not authorise use of the KMS key; decryption still fails without kms:Decrypt. It is tempting because GetObject is the obvious S3 read permission, and it would be correct if the error were an access-denied on the object itself.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.