Courseiva
Security →hardMultiple Select

DVA-C02 Security Practice Question

A company uses AWS KMS to encrypt data in S3. The security team wants to ensure that only specific IAM roles can decrypt the data. Which THREE steps should be taken?

⚠ Common exam trap

Test-takers frequently think IAM policies alone are sufficient for KMS access control, but they forget that KMS key policies are the primary mechanism and must explicitly allow IAM policies to take effect; otherwise, even if an IAM policy grants `kms:Decrypt`, the key policy will deny the request.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a condition in the key policy that allows decrypt only when the principal matches the desired IAM roles.

Key policies in AWS KMS are resource-based policies that directly control access to the CMK. By adding a condition that restricts the `kms:Decrypt` action to only specific IAM roles (using the `aws:PrincipalArn` or `kms:CallerPrincipal` condition key), the security team can ensure that only those roles can decrypt data encrypted with that key. This approach is more secure than relying solely on IAM policies, as key policies are evaluated first and can explicitly deny access even if an IAM policy grants it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add a condition in the key policy that allows decrypt only when the principal matches the desired IAM roles.

    Why this is correct

    A KMS key policy is the primary access control mechanism for a CMK, defining who can use the key and under what conditions. By adding a "Condition" block to the key policy, you can specify that the "kms:Decrypt" action is only allowed when the "aws:PrincipalArn" matches the ARNs of the desired IAM roles. This ensures that even if an IAM user or role has "kms:Decrypt" permission via an IAM policy, the key policy will deny access unless the principal is one of the explicitly allowed roles. This provides a robust, centralized control over key usage.

  • ✗

    Grant all IAM users decrypt permission and rely on S3 bucket policies.

    Why it's wrong here

    Granting "kms:Decrypt" permission to all IAM users is highly insecure because it bypasses the principle of least privilege for key usage. While S3 bucket policies can restrict access to the encrypted objects, they cannot override or restrict who can use the underlying KMS key for decryption. An attacker with access to any IAM user could potentially decrypt data if they gain access to the encrypted S3 objects, regardless of S3 bucket policy restrictions on object access.

  • ✓

    Create an IAM policy that grants kms:Decrypt only to the specific roles.

    Why this is correct

    An IAM policy attached to specific IAM roles can explicitly grant the "kms:Decrypt" permission, allowing only those roles to perform decryption operations. This adheres to the principle of least privilege by limiting the scope of who can request decryption. However, for a principal to successfully decrypt data, both the IAM policy and the KMS key policy must permit the action; the key policy acts as the ultimate authority on key usage.

  • ✓

    Create a customer-managed customer master key (CMK) in KMS.

    Why this is correct

    Creating a customer-managed customer master key (CMK) in AWS KMS is fundamental for implementing fine-grained access control over encryption and decryption operations. Unlike AWS-managed CMKs, which have predefined key policies, customer-managed CMKs allow you to define custom key policies. These custom policies are essential for specifying conditions, such as restricting decryption to specific IAM roles, thereby giving you complete control over the key's usage and lifecycle.

  • ✗

    Use separate CMKs for each IAM role to isolate access.

    Why it's wrong here

    Using separate CMKs for each IAM role to isolate access, while technically feasible, introduces unnecessary operational complexity and increased costs. Managing multiple distinct keys, each with its own lifecycle and policy, becomes cumbersome as the number of roles grows. A single customer-managed CMK with a well-defined key policy utilizing conditions to restrict access based on the principal's ARN or tags provides equivalent security isolation with significantly less management overhead.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DVA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is using AWS KMS to encrypt data in S3. They want to ensure that only specific IAM roles can decrypt the data, even if the IAM role has full S3 access. What should they do?

hard
  • A.Use an IAM policy to deny KMS Decrypt for all users except the role.
  • B.Add a bucket policy that denies Decrypt for all principals except the role.
  • C.Enable S3 Block Public Access on the bucket.
  • ✓ D.Modify the KMS key policy to grant decrypt permission only to the specific IAM role.

Why D: The KMS key policy is the primary access control mechanism for a KMS key, and it must explicitly grant decrypt permission to the IAM role. Even if an IAM role has full S3 access, it cannot decrypt data encrypted with a KMS key unless the key policy allows it (or the key policy delegates to IAM). Therefore, modifying the key policy to grant kms:Decrypt only to the specific role is the correct approach.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.