DVA-C02 Security Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"kms:Decrypt",
"kms:GenerateDataKey"
],
"Resource": "arn:aws:kms:us-east-1:123456789012:key/abcd1234-..."
}
]
}The exhibit shows an IAM policy attached to a Lambda function's execution role. When the Lambda function tries to decrypt data using the KMS key, it receives an access denied error. What is the most likely cause?
⚠ Common exam trap
DVA-C02 often tests KMS access where both IAM policies and key policies are required. Candidates may only check the IAM policy and forget the key policy, leading to access denied errors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The KMS key policy does not grant the Lambda execution role permission to use the key.
The most likely cause is that the KMS key policy does not grant the Lambda execution role permission to use the key. Even if the IAM policy attached to the role includes kms:Decrypt, the KMS key policy must also allow the role to use the key. KMS requires both identity-based and resource-based policies to grant access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy uses an incorrect action name for decryption.
Why it's wrong here
The statement claims the policy uses an incorrect action name for decryption. However, `kms:Decrypt` is the standard and correct action name within AWS KMS for performing decryption operations. If the exhibit shows this action name, then the policy's syntax for the decryption action itself is valid and properly specified, meaning this option incorrectly identifies the source of the problem.
- ✓
The KMS key policy does not grant the Lambda execution role permission to use the key.
Why this is correct
AWS KMS enforces a two-layer authorization model, requiring both an identity-based policy (IAM policy) attached to the principal (like the Lambda execution role) and a resource-based policy (KMS key policy) attached to the key itself to grant permission. Even if the Lambda's IAM policy correctly allows `kms:Decrypt`, if the target KMS key's policy does not also explicitly permit the Lambda's execution role to use the key, the decryption request will be denied. This is a common and critical misconfiguration.
- ✗
The policy does not include kms:DescribeKey permission.
Why it's wrong here
The `kms:DescribeKey` action is used to retrieve metadata about a KMS key, such as its ARN, creation date, and current state. While useful for administrative or auditing purposes, it is not a prerequisite for performing cryptographic operations like decryption. Decrypting data only requires the `kms:Decrypt` permission; therefore, the absence of `kms:DescribeKey` would not cause a decryption failure.
- ✗
The policy does not include kms:Decrypt permission.
Why it's wrong here
This statement asserts that the policy does not include the `kms:Decrypt` permission. However, the context of the question implies that the IAM policy shown in the exhibit *does* contain this essential permission. If `kms:Decrypt` is present in the Lambda function's IAM execution role policy, then the problem lies elsewhere in the authorization chain, not with the direct omission of the primary decryption action from the IAM policy itself.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.