A data engineer is troubleshooting an ETL job that reads from an S3 bucket encrypted with SSE-KMS. The job is failing with an error indicating that the IAM role does not have permission to decrypt the data. What is the most likely missing permission?
SSE-KMS requires the caller to hold kms:Decrypt on the customer-managed key before S3 can return the object. The role's S3 permissions are irrelevant here; the missing KMS grant is what blocks the ETL job's reads.
Why this answer
When an S3 object is encrypted with SSE-KMS, reading the object requires two sets of permissions: s3:GetObject on the object and kms:Decrypt on the KMS key used to encrypt it. The error explicitly states the IAM role lacks permission to decrypt, so the missing permission is kms:Decrypt. Without it, S3 cannot call KMS to decrypt the data key, and the GetObject call fails with AccessDenied.
Exam trap
The trap is assuming that s3:GetObject alone is sufficient to read SSE-KMS encrypted objects, ignoring the separate KMS permission required for decryption.
How to eliminate wrong answers
Option A is wrong because kms:GenerateDataKey is needed for writing (PutObject) with SSE-KMS, not for reading existing encrypted objects. Option B is wrong because s3:ListBucket controls the ability to list objects in a bucket, which is unrelated to decryption and would produce a different error. Option D is wrong because s3:GetObject is the permission to read the object itself; if it were missing, the error would be about S3 access, not KMS decryption.