Courseiva

DOP-C02 Configuration Management and IaC Practice Question

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ec2:DescribeInstances",
        "ec2:StartInstances",
        "ec2:StopInstances"
      ],
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "ssm:GetParameter",
        "ssm:GetParameters"
      ],
      "Resource": "arn:aws:ssm:us-east-1:123456789012:parameter/MyApp/DBPassword"
    }
  ]
}

A DevOps engineer creates the IAM policy above for an instance role. The role is attached to an EC2 instance that runs an application. The application starts and stops EC2 instances and reads a database password from Systems Manager Parameter Store. However, the application fails to retrieve the parameter. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The parameter is a SecureString and the policy does not grant 'kms:Decrypt' permission for the KMS key.

The policy allows 'ssm:GetParameter' and 'ssm:GetParameters' on the specific parameter ARN. However, to retrieve a parameter, the action 'ssm:GetParameter' is sufficient, but the resource ARN must be correct. The given ARN includes the parameter name '/MyApp/DBPassword'. If the application is using a different path or the parameter is encrypted, the policy might be insufficient. But the most common issue is that the parameter is a SecureString and the policy also needs 'kms:Decrypt' access to the KMS key. Option C is correct because the policy does not include KMS permissions. Option A and B are less likely. Option D is incorrect because the actions are allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy does not allow 'ssm:GetParameterHistory'.

    Why it's wrong here

    The action ssm:GetParameterHistory is a separate IAM permission used to retrieve a list of historical versions of a parameter, not the current value. A single call to ssm:GetParameter with the parameter's ARN returns the current value and does not require access to version history. Therefore, even if GetParameterHistory were added, it would not resolve the AccessDenied error caused by a missing KMS decrypt permission for a SecureString parameter.

  • ✗

    The policy does not allow 'ec2:DescribeParameters'.

    Why it's wrong here

    The string 'ec2:DescribeParameters' is not a valid AWS IAM action because the DescribeParameters API operation belongs to the AWS Systems Manager (SSM) service, not EC2, and is named ssm:DescribeParameters. Additionally, EC2 does not have a DescribeParameters action at all; its read actions are things like DescribeInstances, DescribeImages, and DescribeSecurityGroups. Since the action does not exist, the policy would fail validation if it were included, and it is unrelated to the KMS decryption requirement for SecureString parameters.

  • ✓

    The parameter is a SecureString and the policy does not grant 'kms:Decrypt' permission for the KMS key.

    Why this is correct

    When a parameter is stored as a SecureString, its value is encrypted at rest using an AWS KMS key, either the default aws/ssm key or a customer-managed key. To retrieve the plaintext value via ssm:GetParameter, the caller must have kms:Decrypt permission on that specific KMS key, in addition to the ssm:GetParameter action on the parameter resource. The policy shown grants the SSM read action but omits kms:Decrypt, so even though the resource-level SSM permission is correct, the call fails with an AccessDeniedException.

  • ✗

    The policy does not allow 'ssm:GetParameter' on the specific resource.

    Why it's wrong here

    The policy explicitly includes an Allow for ssm:GetParameter on the parameter's Amazon Resource Name (ARN), so resource-level access to the GetParameter action is already granted. This option incorrectly assumes a resource mismatch, but the actual problem is at the KMS layer: SecureString parameters require a separate kms:Decrypt permission on the key that encrypts the value. Without that KMS permission, IAM will deny the decrypt step even though the SSM action is allowed.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.