Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

Exhibit

Refer to the exhibit.
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "kms:Decrypt",
        "kms:GenerateDataKey"
      ],
      "Resource": "arn:aws:kms:us-east-1:123456789012:key/abcd1234-..."
    }
  ]
}

The exhibit shows an IAM policy attached to a Lambda function's execution role. When the Lambda function tries to decrypt data using the KMS key, it receives an access denied error. What is the most likely cause?

⚠ Common exam trap

DVA-C02 often tests KMS access where both IAM policies and key policies are required. Candidates may only check the IAM policy and forget the key policy, leading to access denied errors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The KMS key policy does not grant the Lambda execution role permission to use the key.

The most likely cause is that the KMS key policy does not grant the Lambda execution role permission to use the key. Even if the IAM policy attached to the role includes kms:Decrypt, the KMS key policy must also allow the role to use the key. KMS requires both identity-based and resource-based policies to grant access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy uses an incorrect action name for decryption.

    Why it's wrong here

    The statement claims the policy uses an incorrect action name for decryption. However, `kms:Decrypt` is the standard and correct action name within AWS KMS for performing decryption operations. If the exhibit shows this action name, then the policy's syntax for the decryption action itself is valid and properly specified, meaning this option incorrectly identifies the source of the problem.

  • ✓

    The KMS key policy does not grant the Lambda execution role permission to use the key.

    Why this is correct

    AWS KMS enforces a two-layer authorization model, requiring both an identity-based policy (IAM policy) attached to the principal (like the Lambda execution role) and a resource-based policy (KMS key policy) attached to the key itself to grant permission. Even if the Lambda's IAM policy correctly allows `kms:Decrypt`, if the target KMS key's policy does not also explicitly permit the Lambda's execution role to use the key, the decryption request will be denied. This is a common and critical misconfiguration.

  • ✗

    The policy does not include kms:DescribeKey permission.

    Why it's wrong here

    The `kms:DescribeKey` action is used to retrieve metadata about a KMS key, such as its ARN, creation date, and current state. While useful for administrative or auditing purposes, it is not a prerequisite for performing cryptographic operations like decryption. Decrypting data only requires the `kms:Decrypt` permission; therefore, the absence of `kms:DescribeKey` would not cause a decryption failure.

  • ✗

    The policy does not include kms:Decrypt permission.

    Why it's wrong here

    This statement asserts that the policy does not include the `kms:Decrypt` permission. However, the context of the question implies that the IAM policy shown in the exhibit *does* contain this essential permission. If `kms:Decrypt` is present in the Lambda function's IAM execution role policy, then the problem lies elsewhere in the authorization chain, not with the direct omission of the primary decryption action from the IAM policy itself.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.