Courseiva

DEA-C01 Data Security and Governance Practice Question

A data engineer needs to allow an AWS Lambda function to access a specific AWS KMS customer managed key to decrypt data. The Lambda function assumes an IAM role. Which policy statement should be added to the KMS key policy to grant the necessary permissions with least privilege?

⚠ Common exam trap

The trap here is granting kms:* or adding unnecessary conditions instead of focusing on the specific kms:Decrypt action needed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow the IAM role to perform kms:Decrypt on the KMS key, specifying the role's ARN as the principal.

The KMS key policy must grant the Lambda function's IAM role the kms:Decrypt permission. Specifying the role's ARN as the principal ensures only that role can use the key for decryption. This follows least privilege by not granting unnecessary actions. Other options either grant excessive permissions or add unnecessary conditions that could hinder legitimate access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allow the IAM role to perform kms:Decrypt on the KMS key, with a condition that the request comes from the Lambda function's VPC endpoint.

    Why it's wrong here

    While restricting to a VPC endpoint adds security, it is not the least privilege approach for granting decryption permissions. The condition may inadvertently block legitimate access if the Lambda function uses a different network path. The core requirement is to grant kms:Decrypt to the role, and adding a VPC condition is an unnecessary constraint that could cause failures.

  • ✓

    Allow the IAM role to perform kms:Decrypt on the KMS key, specifying the role's ARN as the principal.

    Why this is correct

    This statement grants the exact permission needed (kms:Decrypt) to the specific IAM role. It follows least privilege by not granting additional actions and by scoping the principal to the role. This is the correct and simplest way to allow the Lambda function to decrypt data using the KMS key.

  • ✗

    Allow the IAM role to perform kms:* on the KMS key, specifying the role's ARN as the principal.

    Why it's wrong here

    Granting kms:* gives full administrative control over the KMS key, including the ability to delete it, change policies, and rotate keys. This violates least privilege. The Lambda function only needs to decrypt data, so kms:Decrypt is sufficient. This option grants excessive permissions and is a security risk.

  • ✗

    Allow the IAM role to perform kms:Decrypt on the KMS key, with a condition that the aws:PrincipalArn matches the role's ARN.

    Why it's wrong here

    Specifying the principal ARN in the key policy already restricts access to that role. Adding a condition on aws:PrincipalArn is redundant and does not enhance least privilege. The key policy principal element should be the role's ARN, and the action should be kms:Decrypt. This option is not wrong but is unnecessarily complex and not the best practice.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.