Courseiva
Design Secure Architectures →mediumMultiple Select

Cross-Account KMS Key Access: Key Policy & IAM Permissions

A central security account stores encrypted log files in S3 using a customer managed AWS KMS key. A partner account already has S3 bucket access through an assumed role and now must also be able to encrypt and decrypt objects that use the same KMS key. Which two actions are required? Select two.

Quick Answer

The answer is that you must attach IAM permissions in the partner account for kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey on the CMK, and also update the KMS key policy in the central account to grant the partner account or its assumed role explicit access. This is required because cross-account KMS key access relies on a two-part authorization model: the key policy must allow the external principal, and that principal must have matching IAM permissions in their own account to invoke the cryptographic operations. On the SAA-C03 exam, this scenario tests your understanding that S3 bucket access alone does not imply KMS key access—a common trap is assuming the partner’s S3 role automatically inherits encryption permissions. The key policy acts as the resource-based gatekeeper, while the partner’s IAM policy provides the identity-based permission; both must align for the decrypt or encrypt call to succeed. Memory tip: think “Key Policy + IAM = Cross-Account Key Access.”

⚠ Common exam trap

The trap here is that candidates often forget that cross-account KMS access requires both a key policy update in the central account AND IAM permissions in the partner account, not just one of them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Update the KMS key policy to allow the partner role or account to use the key.

Option A is correct because a customer managed KMS key's key policy must explicitly grant the partner account or its role permission to use the key; cross-account KMS access is never granted by S3 bucket policies alone, and the key policy is the primary resource-based control that authorizes kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey for the external principal. Option C is correct because the partner account's identity-based IAM policy must also allow the KMS actions (kms:Encrypt, kms:Decrypt, kms:GenerateDataKey) on the CMK's ARN; for cross-account access both the key policy and the caller's IAM policy must permit the operation, so the partner role needs these permissions in addition to the key policy grant. Option B is wrong because automatic key rotation only rotates the backing key material on a schedule and has nothing to do with granting cross-account access. Option D is wrong because replacing the CMK with the AWS managed key alias/aws/s3 removes customer control and cannot be used for cross-account access since its key policy cannot be modified. Option E is wrong because KMS key material for customer managed keys is non-exportable by default and exporting/sharing key material is not the mechanism for cross-account KMS authorization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Update the KMS key policy to allow the partner role or account to use the key.

    Why this is correct

    A customer managed KMS key's access is governed by its key policy, which must explicitly grant the partner account or role permission to use the key. Without this cross-account grant, the partner's IAM policy alone cannot authorise any cryptographic operation on the CMK.

  • ✗

    Enable automatic key rotation to solve the cross-account access requirement.

    Why it's wrong here

    Key rotation re-wraps the CMK's backing key on a schedule; it changes nothing about cross-account authorisation. The partner role still lacks a key policy statement and IAM permission for kms:Encrypt and kms:Decrypt. Rotation is the right action for meeting a compliance interval on a single-account key, not for granting another account usage.

  • ✓

    Attach IAM permissions in the partner account for kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey on the CMK.

    Why this is correct

    Cross-account KMS access requires both sides: the key policy grants the partner account, and the partner's own IAM identity must allow kms:Encrypt, kms:Decrypt and kms:GenerateDataKey on the CMK. This satisfies the requirement to encrypt and decrypt objects using the shared key.

  • ✗

    Replace the CMK with the AWS managed key alias/aws/s3.

    Why it's wrong here

    The AWS managed key alias/aws/s3 cannot be shared cross-account: its key policy is fixed by AWS and grants no external principal access, and it cannot be edited. A customer managed key with an editable key policy is required. The AWS managed key suits single-account default encryption where no cross-account delegation is needed.

  • ✗

    Export the KMS key material and share it with the partner account.

    Why it's wrong here

    Customer managed KMS key material is non-exportable by design, so this action is impossible for a standard CMK. Cross-account use is granted through the key policy plus IAM permissions, not by moving key material. Exportable material applies only to custom key stores backed by CloudHSM, a separate configuration.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SAA-C03

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A central security account stores encrypted log files in S3 using a customer managed AWS KMS key. A partner account already has S3 bucket access through an assumed role and now must also be able to encrypt and decrypt objects that use the same KMS key. Which two actions are required? Select two.

medium
  • ✓ A.Update the KMS key policy to allow the partner role or account to use the key.
  • B.Enable automatic key rotation to solve the cross-account access requirement.
  • ✓ C.Attach IAM permissions in the partner account for kms:Encrypt, kms:Decrypt, and kms:GenerateDataKey on the CMK.
  • D.Replace the CMK with the AWS managed key alias/aws/s3.
  • E.Export the KMS key material and share it with the partner account.

Why A: The KMS key policy must explicitly grant the partner account or its assumed role permission to use the key for cryptographic operations. Without this cross-account policy statement, the partner account cannot access the key even if it has IAM permissions, as KMS key policies are the primary access control mechanism for cross-account usage.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.