DOP-C02 Security and Compliance Practice Question
A company uses a centralized AWS KMS customer master key (CMK) in the security account to encrypt data in S3 buckets across multiple accounts. The S3 buckets are accessed by EC2 instances in the same accounts. The security team wants to ensure that the CMK can only be used by authorized IAM roles in the member accounts. Which policy configuration should be used?
⚠ Common exam trap
DOP-C02 often tests the misconception that an IAM policy in the member account is sufficient for cross-account KMS access, so candidates must remember that the key policy in the owning account must grant permission first and that SCPs only restrict, never grant.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a statement to the KMS key policy that grants the IAM roles in the member accounts permission to use the key.
A KMS key policy is the primary resource-based policy that controls who can use a customer managed key, and it must explicitly grant the member-account IAM roles permission to use the key for cross-account access. Because the CMK lives in the security account and the roles live in member accounts, the key policy must include a statement allowing those external principals to call kms:Decrypt and related actions. Without this key policy statement, IAM policies in the member accounts alone cannot grant access to the cross-account key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach an IAM policy to the IAM roles in the member accounts that allows kms:Decrypt on the CMK.
Why it's wrong here
Without a key policy in the security account that allows the member accounts to use the key, the IAM policy alone is insufficient because KMS requires a key policy that grants access to the principal.
- ✓
Add a statement to the KMS key policy that grants the IAM roles in the member accounts permission to use the key.
Why this is correct
In AWS KMS, a customer master key is always governed by a resource-based key policy in the account that owns the key. To allow principals in separate member accounts to use the CMK, the key policy must include a statement whose Principal element contains the ARN of the IAM role (or the member account root) and grants the required cryptographic actions, such as kms:Decrypt. This acts as the cross-account authorization; additionally, the member account's IAM policy must delegate those same actions to the role, because KMS requires that both the key policy allow the principal and the principal's IAM policy allow the action.
- ✗
Create a service control policy (SCP) that allows kms:Decrypt for the CMK.
Why it's wrong here
Service control policies (SCPs) are authorization boundaries in AWS Organizations that filter which permissions a principal can receive from IAM, but they never grant permissions on their own. Even if an SCP explicitly allows kms:Decrypt, the KMS key policy is still the definitive resource-based authority; without a key policy statement that identifies the member-account roles as principals, the operation fails with an access denied. SCPs only constrain IAM policies, so an SCP cannot be used to add a grant or permission to use a specific CMK.
- ✗
Use a VPC endpoint policy for KMS to allow access from the member accounts' VPCs.
Why it's wrong here
A VPC endpoint policy for the KMS interface endpoint controls which actions, resources, and principals are allowed through the endpoint, functioning as a filter on network-level API calls. It cannot create or bestow KMS authorization because KMS evaluates the key policy, and then IAM policies, to determine whether a caller may use the key. Even if the endpoint policy allows kms:Decrypt on the CMK, nothing in the key policy grants the member-account roles permission, so requests will still be rejected by the KMS service.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.