DVA-C02 Security Practice Question
A company uses AWS KMS to encrypt data in S3. The security team wants to ensure that only specific IAM roles can decrypt the data. Which THREE steps should be taken?
⚠ Common exam trap
Test-takers frequently think IAM policies alone are sufficient for KMS access control, but they forget that KMS key policies are the primary mechanism and must explicitly allow IAM policies to take effect; otherwise, even if an IAM policy grants `kms:Decrypt`, the key policy will deny the request.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a condition in the key policy that allows decrypt only when the principal matches the desired IAM roles.
Key policies in AWS KMS are resource-based policies that directly control access to the CMK. By adding a condition that restricts the `kms:Decrypt` action to only specific IAM roles (using the `aws:PrincipalArn` or `kms:CallerPrincipal` condition key), the security team can ensure that only those roles can decrypt data encrypted with that key. This approach is more secure than relying solely on IAM policies, as key policies are evaluated first and can explicitly deny access even if an IAM policy grants it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Add a condition in the key policy that allows decrypt only when the principal matches the desired IAM roles.
Why this is correct
A KMS key policy is the primary access control mechanism for a CMK, defining who can use the key and under what conditions. By adding a "Condition" block to the key policy, you can specify that the "kms:Decrypt" action is only allowed when the "aws:PrincipalArn" matches the ARNs of the desired IAM roles. This ensures that even if an IAM user or role has "kms:Decrypt" permission via an IAM policy, the key policy will deny access unless the principal is one of the explicitly allowed roles. This provides a robust, centralized control over key usage.
- ✗
Grant all IAM users decrypt permission and rely on S3 bucket policies.
Why it's wrong here
Granting "kms:Decrypt" permission to all IAM users is highly insecure because it bypasses the principle of least privilege for key usage. While S3 bucket policies can restrict access to the encrypted objects, they cannot override or restrict who can use the underlying KMS key for decryption. An attacker with access to any IAM user could potentially decrypt data if they gain access to the encrypted S3 objects, regardless of S3 bucket policy restrictions on object access.
- ✓
Create an IAM policy that grants kms:Decrypt only to the specific roles.
Why this is correct
An IAM policy attached to specific IAM roles can explicitly grant the "kms:Decrypt" permission, allowing only those roles to perform decryption operations. This adheres to the principle of least privilege by limiting the scope of who can request decryption. However, for a principal to successfully decrypt data, both the IAM policy and the KMS key policy must permit the action; the key policy acts as the ultimate authority on key usage.
- ✓
Create a customer-managed customer master key (CMK) in KMS.
Why this is correct
Creating a customer-managed customer master key (CMK) in AWS KMS is fundamental for implementing fine-grained access control over encryption and decryption operations. Unlike AWS-managed CMKs, which have predefined key policies, customer-managed CMKs allow you to define custom key policies. These custom policies are essential for specifying conditions, such as restricting decryption to specific IAM roles, thereby giving you complete control over the key's usage and lifecycle.
- ✗
Use separate CMKs for each IAM role to isolate access.
Why it's wrong here
Using separate CMKs for each IAM role to isolate access, while technically feasible, introduces unnecessary operational complexity and increased costs. Managing multiple distinct keys, each with its own lifecycle and policy, becomes cumbersome as the number of roles grows. A single customer-managed CMK with a well-defined key policy utilizing conditions to restrict access based on the principal's ARN or tags provides equivalent security isolation with significantly less management overhead.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DVA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is using AWS KMS to encrypt data in S3. They want to ensure that only specific IAM roles can decrypt the data, even if the IAM role has full S3 access. What should they do?
hard- A.Use an IAM policy to deny KMS Decrypt for all users except the role.
- B.Add a bucket policy that denies Decrypt for all principals except the role.
- C.Enable S3 Block Public Access on the bucket.
- ✓ D.Modify the KMS key policy to grant decrypt permission only to the specific IAM role.
Why D: The KMS key policy is the primary access control mechanism for a KMS key, and it must explicitly grant decrypt permission to the IAM role. Even if an IAM role has full S3 access, it cannot decrypt data encrypted with a KMS key unless the key policy allows it (or the key policy delegates to IAM). Therefore, modifying the key policy to grant kms:Decrypt only to the specific role is the correct approach.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.