DVA-C02 Security Practice Question
Network Topology
Refer to the exhibit. A developer runs the AWS CLI command to decrypt a file using a KMS key. The command fails with an AccessDeniedException. What is the most likely cause?
⚠ Common exam trap
Candidates often confuse AccessDeniedException with other KMS errors. For example, a disabled key throws DisabledException, and an invalid or improperly encoded ciphertext throws InvalidCiphertextException. AccessDeniedException specifically points to an authorization/permission issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM user 'DevUser' does not have the kms:Decrypt permission on the KMS key.
An AccessDeniedException indicates that the IAM identity (user or role) making the request lacks the required kms:Decrypt permission on the specified KMS key. KMS key policies and IAM policies must both allow the action for the call to succeed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The IAM user 'DevUser' does not have the kms:Decrypt permission on the KMS key.
Why this is correct
The error message "User: arn:aws:iam::123456789012:user/DevUser is not authorized to perform: kms:Decrypt" explicitly indicates that the IAM principal attempting the operation lacks the necessary kms:Decrypt permission. This typically means either the IAM policy attached to 'DevUser' does not grant kms:Decrypt on the specific KMS key, or the KMS key policy itself does not permit 'DevUser' to perform this action. For a KMS operation to succeed, both the IAM identity's policy and the KMS key's resource policy must explicitly allow the requested action.
- ✗
The ciphertext blob is not base64-encoded.
Why it's wrong here
The fileb:// prefix used with the ciphertext-blob parameter instructs the AWS CLI to read the specified file as raw binary data, which is the correct format for a KMS ciphertext blob. Therefore, manual base64 encoding of the ciphertext is not required when using fileb://. If the ciphertext itself were malformed or corrupted, the error would likely be a ValidationException or InvalidCiphertextException, not an authorization error, as the service would fail to parse the data before checking permissions.
- ✗
The KMS key is disabled.
Why it's wrong here
If the KMS key were disabled, the AWS CLI command would return a different error message, specifically a KMSInvalidStateException indicating "Key is disabled." The current error message, "User: ... is not authorized to perform: kms:Decrypt," clearly points to a permissions issue with the IAM user or the key policy, rather than the operational state of the KMS key itself. A disabled key prevents all cryptographic operations, regardless of permissions.
- ✗
The KMS key ID is incorrect.
Why it's wrong here
An incorrect or non-existent KMS key ID would typically result in a NotFoundException or ValidationException error, indicating that the specified key could not be found or identified by AWS KMS. The error message provided, however, explicitly references the correct KMS key ARN and then states an authorization failure for that specific resource. This confirms that the key ID was valid and the service successfully identified the key, but the principal lacked permission to use it.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DVA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A developer runs the AWS CLI command to decrypt a file using a KMS key. What is the most likely cause of the error?
medium- A.The encrypted file is corrupted.
- B.The CLI cannot read the file.
- ✓ C.The IAM user lacks kms:Decrypt permission on the key.
- D.The KMS key ID is incorrect.
Why C: The IAM user DevUser does not have kms:Decrypt permission on the specified KMS key.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.