SAA-C03 Design Secure Architectures Practice Question
Your AWS Organizations environment has an SCP that explicitly denies kms:Decrypt for principals in the Production OU. A member account IAM policy for a user grants kms:Decrypt on the required KMS key. If that user attempts kms:Decrypt, what happens?
⚠ Common exam trap
A common mix-up: candidates assume IAM policy allows are sufficient, forgetting that SCPs act as a higher-level permission boundary that can override those allows with an explicit deny.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The request is denied because the SCP explicit deny overrides IAM allows
In AWS Organizations, Service Control Policies (SCPs) act as a guardrail that sets the maximum available permissions for all accounts in an OU. An explicit deny in an SCP overrides any allow in an IAM policy, even if the IAM policy explicitly grants the action. Therefore, the user's kms:Decrypt request is denied because the SCP's explicit deny takes precedence over the IAM allow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The request succeeds because the IAM policy explicitly allows kms:Decrypt
Why it's wrong here
An IAM policy that explicitly allows kms:Decrypt governs what a principal can do within an account, but AWS Organizations SCPs operate as an outer authorization boundary for all principals in a member account. When an SCP contains an explicit Deny that matches kms:Decrypt, that Deny takes precedence over any Allow found in the account's identity-based or resource-based policies. The final authorization decision is effectively 'deny' because the explicit Deny in the SCP cannot be overridden by a permissive IAM statement, regardless of how explicit the IAM allow is.
- ✓
The request is denied because the SCP explicit deny overrides IAM allows
Why this is correct
SCPs are evaluated as a permissions filter for the member account. When an SCP contains an explicit Deny matching kms:Decrypt, that Deny takes precedence over any IAM Allow decisions in the account, and the action is blocked.
- ✗
The request succeeds, but only when using the KMS key policy to allow the user
Why it's wrong here
Whether the KMS key policy allows the user is separate from the Organizations authorization filter. Even if the key policy would allow kms:Decrypt, the SCP’s explicit deny blocks the request at a higher level in the authorization flow.
- ✗
The request succeeds for read-only actions and fails only for writes
Why it's wrong here
SCP evaluation is based on the exact action string specified in the policy, not on whether the action is conceptually a read or write operation. The SCP in question explicitly denies kms:Decrypt, and that exact action is what the request calls, so the request fails. Treating kms:Decrypt as 'read-only' would not change the outcome because the SCP matches on the Action element value; there is no special handling for read-like or write-like operations. In AWS authorization, every action is denied by default unless an Allow is found that is not contradicted by a Deny, and a Deny in an SCP is decisive regardless of the action's classification.
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.