DEA-C01 Data Security and Governance Practice Question
Exhibit
{
"Effect": "Allow",
"Action": ["kms:Decrypt"],
"Resource": "*",
"Condition": {
"ForAnyValue:StringEquals": {
"kms:EncryptionContextKeys": ["service", "aws:pi"],
"kms:EncryptionContext": {
"aws:pi": "db-123"
}
}
}
}Refer to the exhibit. An IAM policy includes the above statement to allow decryption of a KMS key under specific conditions. What does this policy allow?
⚠ Common exam trap
DEA-C01 often tests the misunderstanding of encryption context conditions in IAM policies. Candidates may think the policy allows decryption of any data with the key, but the condition restricts it to a specific context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Decrypt data that was encrypted with the encryption context {"aws:pi":"db-123"}
The policy allows the kms:Decrypt action only when the encryption context matches the specified key-value pair. The condition likely uses the StringEquals condition operator on the kms:EncryptionContext:aws:pi key with value db-123. This means decryption is permitted only for ciphertext that was encrypted with that exact encryption context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Decrypt any data encrypted with any KMS key
Why it's wrong here
The statement names one specific key resource and attaches encryption-context conditions, so decryption is confined to that key and matching context. Wildcard scope would require a "Resource": "*" entry and no condition block. Such unrestricted decrypt policies suit accounts needing broad key access.
- ✓
Decrypt data that was encrypted with the encryption context {"aws:pi":"db-123"}
Why this is correct
The policy's condition matches the encryption context key-value pair aws:pi equal to db-123, so kms:Decrypt succeeds only for ciphertext whose encryption context includes that exact pair, binding decryption to data encrypted under the same context.
- ✗
Encrypt data with the KMS key using the specified encryption context
Why it's wrong here
The statement's action is kms:Decrypt, so it authorises decryption only; kms:Encrypt is a separate action that must be named explicitly in a policy statement. Encryption context conditions restrict which decrypt calls succeed. Encrypt permission is the right answer when the policy lists kms:Encrypt as its action.
- ✗
Decrypt data encrypted with the KMS key without any encryption context
Why it's wrong here
The statement's condition keys constrain decryption to requests carrying the specified encryption context; a call omitting that context fails the condition and is denied. Encryption context binds ciphertext to key-value pairs. Decrypting without context is permitted only by a policy lacking such condition blocks.
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.