Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company is using AWS KMS to encrypt data in Amazon S3. The security team wants to ensure that only a specific IAM role can decrypt the data. What is the MOST secure way to enforce this?

⚠ Common exam trap

SCS-C02 often tests the misconception that an IAM policy alone can grant KMS decrypt access, when in fact the KMS key policy must also allow the principal — key policy is the gatekeeper.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the KMS key policy with a condition that allows only the role to decrypt

AWS KMS key policies are the primary resource-based access control for a KMS key. To ensure only a specific IAM role can decrypt, the key policy must explicitly allow that role (and no other principals) for kms:Decrypt, optionally with conditions. IAM policies alone cannot grant access to a KMS key unless the key policy also permits it, making the key policy the authoritative enforcement point.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach an IAM policy to the role granting kms:Decrypt

    Why it's wrong here

    Attaching an IAM policy to the role that grants kms:Decrypt only changes the role's permissions; it does nothing to constrain other IAM principals. If the KMS key policy already permits another user or service to decrypt, that principal can still use the key. KMS authorization requires both an IAM policy (for IAM users/roles) and a key policy that allows that principal, so this approach may enable the role but fails to restrict decryption to it alone.

  • ✓

    Configure the KMS key policy with a condition that allows only the role to decrypt

    Why this is correct

    A KMS key policy is the resource-based policy that ultimately defines which principals are allowed to use the key. By adding a condition such as aws:PrincipalArn to the kms:Decrypt action, you can limit the permission to a specific IAM role ARN, ensuring that no other principal can invoke decrypt even if they have IAM permissions. The key policy, not IAM, is the controlling restriction here. Always include a statement allowing the account root user to administer the key so you don't lock yourself out.

  • ✗

    Disable the KMS key and re-enable it only when the role needs to decrypt

    Why it's wrong here

    Disabling a KMS key immediately blocks all cryptographic operations, including decryption for every principal, and re-enabling requires manual, often multi-step approval processes. This is impractical as a routine access control mechanism because it introduces downtime, availability risks, and operational overhead. It also cannot distinguish between authorized and unauthorized users—the key is simply off for everyone. Access should be granted or revoked through key policies and IAM policies, not by toggling the key's enabled state.

  • ✗

    Configure an S3 bucket policy that denies all principals except the role

    Why it's wrong here

    An S3 bucket policy controls access at the object level but does not govern who can decrypt the KMS-encrypted data; decryption is authorised solely by a KMS key policy or IAM policy attached to the KMS key. This option is tempting because bucket policies are commonly used to restrict S3 access to a specific IAM role, and in a scenario where data is stored unencrypted, such a policy would effectively limit read access. However, it fails here because the encryption layer (KMS) operates independently of S3 permissions, so the role could still be blocked from decrypting if the KMS key policy does not grant it decrypt permission.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.