Courseiva
Security →mediumMultiple Select

DVA-C02 Security Practice Question

A company is using AWS KMS to encrypt data in S3. Which TWO actions are required to allow an IAM user to decrypt objects in a specific S3 bucket?

⚠ Common exam trap

The trap here is that candidates often forget that decrypting an SSE-KMS encrypted object requires both S3 read permissions and KMS decrypt permissions, leading them to select only one of the two required actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach a policy to the user allowing s3:GetObject on the bucket.

To decrypt an object stored in S3 using server-side encryption with AWS KMS (SSE-KMS), the IAM user must have the s3:GetObject permission to retrieve the encrypted object from the bucket. Without this permission, the user cannot even initiate the GetObject request, regardless of KMS permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Attach a policy to the user allowing s3:GetObject on the bucket.

    Why this is correct

    To retrieve any object from an S3 bucket, regardless of its encryption status, the principal (user or role) must have explicit permission to perform the s3:GetObject action. This action grants the ability to download the object's data, which is a fundamental prerequisite before any decryption process can even begin. Without this permission, S3 will deny the request to access the object entirely, making decryption impossible.

  • ✗

    Attach a policy to the user allowing kms:Encrypt.

    Why it's wrong here

    The kms:Encrypt permission allows a principal to encrypt plaintext data using a KMS key, typically as part of an upload or data processing workflow. However, the question specifically asks what is needed to *decrypt* existing data. Encrypting data is the opposite operation and is not required when a user simply needs to retrieve and decrypt an already encrypted object from S3.

  • ✗

    Attach a policy to the user allowing s3:PutObject.

    Why it's wrong here

    The s3:PutObject permission grants a principal the ability to upload new objects or overwrite existing objects in an S3 bucket. The scenario describes a user needing to access and decrypt *existing* encrypted data, which is a read operation. Uploading or modifying objects (a write operation) is entirely unrelated to the process of retrieving and decrypting data, making this permission unnecessary for the stated goal.

  • ✗

    Attach a policy to the user allowing kms:GenerateDataKey.

    Why it's wrong here

    The kms:GenerateDataKey permission allows a principal to request KMS to generate a unique data key, which is then used for client-side encryption of data. This action is typically performed when *encrypting* new data, not when decrypting it. When decrypting, the encrypted data key (stored alongside the object in S3) is sent to KMS for decryption, not a request to generate a *new* data key.

  • ✓

    Attach a policy to the user allowing kms:Decrypt on the KMS key.

    Why this is correct

    When an S3 object is encrypted with AWS KMS (SSE-KMS), the encrypted data key is stored with the object metadata. Upon retrieval, S3 sends this encrypted data key to KMS for decryption. Therefore, the principal attempting to retrieve the object must have explicit kms:Decrypt permission on the specific KMS key used to encrypt the object, allowing KMS to decrypt the data key and return it to S3.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.