Courseiva

DVA-C02 Troubleshooting and Optimization Practice Question

Exhibit

Refer to the exhibit.

IAM policy JSON:
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "S3Access",
            "Effect": "Allow",
            "Action": [
                "s3:GetObject",
                "s3:PutObject"
            ],
            "Resource": "arn:aws:s3:::my-bucket/*"
        },
        {
            "Sid": "KMSDecrypt",
            "Effect": "Allow",
            "Action": "kms:Decrypt",
            "Resource": "arn:aws:kms:us-east-1:123456789012:key/abc123"
        }
    ]
}

The exhibit shows an IAM policy attached to a Lambda function's execution role. The function writes objects to an S3 bucket that is encrypted with a KMS key (the key specified in the policy). When the function tries to write an object, it receives an access denied error. What is the MOST likely missing permission?

⚠ Common exam trap

DVA-C02 often tests the misconception that S3 permissions alone are sufficient for encrypted buckets — candidates forget that SSE-KMS writes also require kms:GenerateDataKey (and reads require kms:Decrypt).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kms:GenerateDataKey is missing.

When writing an object to an S3 bucket encrypted with SSE-KMS, the caller must have kms:GenerateDataKey permission so S3 can obtain a data key to encrypt the object. Without it, the write fails with AccessDenied even if s3:PutObject is granted. The other options either describe a different failure mode or a permission not required for a simple PutObject.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    kms:GenerateDataKey is missing.

    Why this is correct

    When S3 performs server-side encryption with AWS KMS (SSE-KMS), it requires the calling principal, such as the Lambda function's execution role, to have the kms:GenerateDataKey permission. This specific permission allows S3 to request a unique data key from KMS to encrypt the object data itself. Without this crucial permission, S3 cannot obtain the necessary encryption key to perform the server-side encryption during the PutObject operation, leading to a failure.

  • ✗

    The KMS key policy does not allow the Lambda function role.

    Why it's wrong here

    While a restrictive KMS key policy could indeed prevent the Lambda function from utilizing the key, the immediate and more direct cause of failure, as implied by a missing permission, lies with the IAM policy attached to the Lambda function's execution role. If the IAM policy itself does not grant the necessary kms:GenerateDataKey permission, then the Lambda function cannot even attempt to perform the action, regardless of how permissive the KMS key policy might be. The IAM policy defines the maximum permissions the role can ever assume.

  • ✗

    s3:GetObject is missing for the bucket.

    Why it's wrong here

    The s3:GetObject permission is specifically designed for retrieving or downloading objects from an S3 bucket. The scenario describes a Lambda function attempting to write an object to S3, which is an upload operation. For writing operations, the s3:PutObject permission is required, not s3:GetObject. Therefore, the absence of s3:GetObject is entirely irrelevant to the failure of an object write operation, as it serves a different purpose.

  • ✗

    kms:ReEncrypt is missing.

    Why it's wrong here

    The kms:ReEncrypt permission is specifically utilized when data that has already been encrypted under one AWS KMS key needs to be decrypted and then re-encrypted under a different KMS key. For an initial PutObject operation to S3 using server-side encryption with KMS (SSE-KMS), the data is being encrypted for the very first time. Since no prior encryption under a different key exists, the kms:ReEncrypt permission is not applicable or required for this initial write process.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.