DEA-C01 SSE-KMS Practice Question
An organization is using AWS Glue to process sensitive data. The data is stored in S3 with server-side encryption using AWS KMS (SSE-KMS). The Glue job fails with an error indicating that it cannot read the data. The IAM role used by Glue has the following policy. What is missing?
⚠ Common exam trap
DEA-C01 often tests the misconception that s3:GetObject alone is sufficient to read SSE-KMS encrypted objects, when in fact kms:Decrypt on the KMS key is also mandatory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The kms:Decrypt permission on the KMS key
The Glue job fails because the IAM role lacks the kms:Decrypt permission on the KMS key used for SSE-KMS encryption. When S3 objects are encrypted with SSE-KMS, any principal reading the object must have both s3:GetObject on the object and kms:Decrypt on the KMS key. Without kms:Decrypt, S3 returns an AccessDenied error even though the s3:GetObject permission is present.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The s3:GetObject permission on the bucket
Why it's wrong here
The stem states the job fails reading SSE-KMS encrypted data, so object-level read access is not the gap; s3:GetObject alone cannot decrypt KMS-protected objects. This permission is the correct fix for unencrypted buckets or SSE-S3, where no KMS authorisation is involved.
- ✓
The kms:Decrypt permission on the KMS key
Why this is correct
Reading SSE-KMS encrypted S3 objects requires both S3 GetObject and kms:Decrypt on the customer managed key. The Glue execution role's policy grants S3 access but omits the KMS decrypt action, so the job cannot unwrap the data key and fails with an access-denied error.
- ✗
The kms:GenerateDataKey permission on the KMS key
Why it's wrong here
Reading SSE-KMS objects requires kms:Decrypt, not kms:GenerateDataKey, which only produces data keys for encrypting new objects. The Glue job is decrypting existing data, so granting this permission leaves the read failure unresolved. GenerateDataKey suits writers encrypting objects.
- ✗
The kms:ReEncrypt permission on the KMS key
Why it's wrong here
kms:ReEncrypt is needed only when changing a key or encryption context, which this read-only Glue job does not do. Decryption of SSE-KMS objects depends on kms:Decrypt, so this permission does not address the failure. ReEncrypt suits key-rotation or cross-account copy workflows.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,321 original DEA-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.