Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company uses a centralized AWS KMS customer master key (CMK) in the security account to encrypt data in S3 buckets across multiple accounts. The S3 buckets are accessed by EC2 instances in the same accounts. The security team wants to ensure that the CMK can only be used by authorized IAM roles in the member accounts. Which policy configuration should be used?

⚠ Common exam trap

DOP-C02 often tests the misconception that an IAM policy in the member account is sufficient for cross-account KMS access, so candidates must remember that the key policy in the owning account must grant permission first and that SCPs only restrict, never grant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a statement to the KMS key policy that grants the IAM roles in the member accounts permission to use the key.

A KMS key policy is the primary resource-based policy that controls who can use a customer managed key, and it must explicitly grant the member-account IAM roles permission to use the key for cross-account access. Because the CMK lives in the security account and the roles live in member accounts, the key policy must include a statement allowing those external principals to call kms:Decrypt and related actions. Without this key policy statement, IAM policies in the member accounts alone cannot grant access to the cross-account key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach an IAM policy to the IAM roles in the member accounts that allows kms:Decrypt on the CMK.

    Why it's wrong here

    Without a key policy in the security account that allows the member accounts to use the key, the IAM policy alone is insufficient because KMS requires a key policy that grants access to the principal.

  • ✓

    Add a statement to the KMS key policy that grants the IAM roles in the member accounts permission to use the key.

    Why this is correct

    In AWS KMS, a customer master key is always governed by a resource-based key policy in the account that owns the key. To allow principals in separate member accounts to use the CMK, the key policy must include a statement whose Principal element contains the ARN of the IAM role (or the member account root) and grants the required cryptographic actions, such as kms:Decrypt. This acts as the cross-account authorization; additionally, the member account's IAM policy must delegate those same actions to the role, because KMS requires that both the key policy allow the principal and the principal's IAM policy allow the action.

  • ✗

    Create a service control policy (SCP) that allows kms:Decrypt for the CMK.

    Why it's wrong here

    Service control policies (SCPs) are authorization boundaries in AWS Organizations that filter which permissions a principal can receive from IAM, but they never grant permissions on their own. Even if an SCP explicitly allows kms:Decrypt, the KMS key policy is still the definitive resource-based authority; without a key policy statement that identifies the member-account roles as principals, the operation fails with an access denied. SCPs only constrain IAM policies, so an SCP cannot be used to add a grant or permission to use a specific CMK.

  • ✗

    Use a VPC endpoint policy for KMS to allow access from the member accounts' VPCs.

    Why it's wrong here

    A VPC endpoint policy for the KMS interface endpoint controls which actions, resources, and principals are allowed through the endpoint, functioning as a filter on network-level API calls. It cannot create or bestow KMS authorization because KMS evaluates the key policy, and then IAM policies, to determine whether a caller may use the key. Even if the endpoint policy allows kms:Decrypt on the CMK, nothing in the key policy grants the member-account roles permission, so requests will still be rejected by the KMS service.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.