Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company is using AWS Key Management Service (KMS) to encrypt data at rest in Amazon S3. The security team wants to ensure that only a specific IAM role can decrypt the data. Which KMS policy element should be used?

⚠ Common exam trap

Many exam-takers confuse the Principal element with the Resource element, thinking Resource controls who can use the key, when in fact Resource identifies the key itself and Principal identifies the entity allowed to act on it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Principal

(Principal) is correct because in a KMS key policy, the Principal element specifies which IAM users, roles, or AWS services are allowed to perform actions on the key. By setting the Principal to the specific IAM role's ARN, only that role can decrypt the data, enforcing the security team's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Principal

    Why this is correct

    The Principal element in a KMS key policy identifies the IAM role, user, service, or account that is explicitly granted permission to use the key. For example, the ARN of an IAM role is placed here so that role can call kms:Encrypt or kms:Decrypt. Since the question asks who can use the key, Principal is the correct answer.

  • ✗

    Resource

    Why it's wrong here

    The Resource element in a KMS key policy specifies the AWS KMS key itself, usually by its key ARN, and defines what object the statement applies to. KMS key policies are resource-based policies attached to a single key, so the Resource can only be that key's ARN or a wildcard, never the caller. This element tells KMS which key is affected, not which identity is allowed, so it is incorrect.

  • ✗

    Action

    Why it's wrong here

    The Action element enumerates the specific KMS API operations that the policy permits, such as kms:Encrypt, kms:Decrypt, kms:ReEncrypt, or kms:GenerateDataKey. It governs what operations can be performed, not who can perform them, and it only takes effect when paired with a Principal. Because this statement is about the identity using the key, Action cannot be the correct answer.

  • ✗

    Effect

    Why it's wrong here

    The Effect element is the allow-or-deny decision in a policy statement, written as Allow or Deny. It sets the outcome when a request matches the Principal, Action, Resource, and Condition, but it says nothing about which identities are permitted to use the key. Because it does not identify the user or role, Effect is not the correct answer.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.