DVA-C02 Security Practice Question
A company is using AWS KMS to encrypt data in S3. Which TWO actions are required to allow an IAM user to decrypt objects in a specific S3 bucket?
⚠ Common exam trap
The trap here is that candidates often forget that decrypting an SSE-KMS encrypted object requires both S3 read permissions and KMS decrypt permissions, leading them to select only one of the two required actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach a policy to the user allowing s3:GetObject on the bucket.
To decrypt an object stored in S3 using server-side encryption with AWS KMS (SSE-KMS), the IAM user must have the s3:GetObject permission to retrieve the encrypted object from the bucket. Without this permission, the user cannot even initiate the GetObject request, regardless of KMS permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attach a policy to the user allowing s3:GetObject on the bucket.
Why this is correct
To retrieve any object from an S3 bucket, regardless of its encryption status, the principal (user or role) must have explicit permission to perform the s3:GetObject action. This action grants the ability to download the object's data, which is a fundamental prerequisite before any decryption process can even begin. Without this permission, S3 will deny the request to access the object entirely, making decryption impossible.
- ✗
Attach a policy to the user allowing kms:Encrypt.
Why it's wrong here
The kms:Encrypt permission allows a principal to encrypt plaintext data using a KMS key, typically as part of an upload or data processing workflow. However, the question specifically asks what is needed to *decrypt* existing data. Encrypting data is the opposite operation and is not required when a user simply needs to retrieve and decrypt an already encrypted object from S3.
- ✗
Attach a policy to the user allowing s3:PutObject.
Why it's wrong here
The s3:PutObject permission grants a principal the ability to upload new objects or overwrite existing objects in an S3 bucket. The scenario describes a user needing to access and decrypt *existing* encrypted data, which is a read operation. Uploading or modifying objects (a write operation) is entirely unrelated to the process of retrieving and decrypting data, making this permission unnecessary for the stated goal.
- ✗
Attach a policy to the user allowing kms:GenerateDataKey.
Why it's wrong here
The kms:GenerateDataKey permission allows a principal to request KMS to generate a unique data key, which is then used for client-side encryption of data. This action is typically performed when *encrypting* new data, not when decrypting it. When decrypting, the encrypted data key (stored alongside the object in S3) is sent to KMS for decryption, not a request to generate a *new* data key.
- ✓
Attach a policy to the user allowing kms:Decrypt on the KMS key.
Why this is correct
When an S3 object is encrypted with AWS KMS (SSE-KMS), the encrypted data key is stored with the object metadata. Upon retrieval, S3 sends this encrypted data key to KMS for decryption. Therefore, the principal attempting to retrieve the object must have explicit kms:Decrypt permission on the specific KMS key used to encrypt the object, allowing KMS to decrypt the data key and return it to S3.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.