SCS-C02 Data Protection Practice Question
A company is using AWS KMS to encrypt data at rest in Amazon S3. The security team wants to ensure that only a specific IAM role can decrypt objects in a particular S3 bucket. Which policy should be attached to the KMS key to enforce this restriction?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
KMS key policy with a condition that the principal must be the specific IAM role
KMS key policies are the main mechanism to control access to KMS keys. By specifying the IAM role as the principal in a key policy statement for the kms:Decrypt action, only that role can decrypt using the key. Option A is incorrect because KMS grants are intended for temporary or cross-account access and are not the best practice for permanent control. Option B is incorrect because IAM policies alone are not sufficient if the key policy does not allow the role; both policies must align. Option C is incorrect because S3 bucket policies control access to S3 operations, not KMS decryption permissions directly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
KMS grant that gives the IAM role decrypt permissions for the key
Why it's wrong here
KMS grants are temporary permissions that allow a principal to use a KMS key for specific operations, but they are not intended as a permanent access-control mechanism. Grants are created and managed separately from IAM roles, can be retired or revoked by the grantor, and require an additional API call to create. Because the question involves a long-term requirement for an IAM role to decrypt, a grant is the wrong mechanism; key policies or IAM policies with proper key-policy support are the appropriate tools.
- ✗
IAM policy attached to the role that allows kms:Decrypt for the key
Why it's wrong here
An IAM policy alone cannot grant kms:Decrypt because KMS key policies act as a separate authorization boundary. If the key policy does not explicitly allow the IAM role (or allow the account root to delegate via IAM), any IAM allow is effectively ignored. KMS requires that both the key policy and the requesting identity's IAM policy permit the action, so a role policy must be paired with a key policy that authorizes the role. Simply attaching an IAM policy is insufficient when the key policy restricts access to specific principals.
- ✗
S3 bucket policy that denies decrypt unless the requester is the specific IAM role
Why it's wrong here
S3 bucket policies govern access to S3 resources such as buckets and objects, not to AWS KMS keys. A condition in an S3 bucket policy cannot affect kms:Decrypt because that is a KMS action evaluated by KMS, not S3. Even if an S3 policy included a denial, it would not prevent a caller from decrypting via KMS—only KMS key policies, IAM policies, and KMS grants can control that operation. Thus this option is a fundamental misunderstanding of service boundaries.
- ✓
KMS key policy with a condition that the principal must be the specific IAM role
Why this is correct
A KMS key policy that explicitly lists the IAM role as Principal, optionally with a condition like aws:PrincipalArn, correctly restricts kms:Decrypt to that role. Key policies are the authoritative control for a KMS key, and when they grant access to a specific principal, IAM policies are not required for that identity to decrypt. This is the recommended approach when the desired access is limited to a particular role and you want the key policy to be self-contained and auditable. Since the key policy is evaluated first and any IAM allow is subordinate to it, this configuration unambiguously enforces the intended restriction.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.