SCS-C02 Data Protection Practice Question
A company needs to share an encrypted Amazon S3 object with another AWS account. The object is encrypted with an AWS KMS customer managed key. Which steps are required?
⚠ Common exam trap
SCS-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access to KMS-encrypted objects, ignoring the separate KMS key policy authorization boundary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update both the bucket policy and the KMS key policy to grant cross-account access.
Cross-account access to a KMS-encrypted S3 object requires permissions on both sides: the S3 bucket policy must grant the external account s3:GetObject, and the KMS key policy must grant that account kms:Decrypt. Without the KMS key policy update, the external account's request fails with AccessDenied even if the bucket policy allows it, because S3 delegates decryption authorization to KMS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use an object ACL to grant the other account read access.
Why it's wrong here
An object ACL can only grant the other account permission to issue s3:GetObject against the object; it cannot convey anything about the KMS key. Because the object is encrypted with SSE-KMS, the external principal must also be allowed by the KMS key policy to call kms:Decrypt (and the external IAM identity needs its own kms:Decrypt permission). Object ACLs are also a legacy mechanism that AWS recommends against for cross-account sharing, and they are disabled by default when S3 Object Ownership is set to bucket owner enforced.
- ✓
Update both the bucket policy and the KMS key policy to grant cross-account access.
Why this is correct
The correct cross-account configuration requires two resource-based policies that address separate authorization layers: the bucket policy must explicitly allow the external account's principal to call s3:GetObject on the object, and the KMS key policy must explicitly allow that same external principal to call kms:Decrypt. The bucket policy authorizes the S3 data-plane operation, while the KMS key policy authorizes the cryptographic operation that S3 performs on the requester's behalf. Without either policy, the request fails because the external account is not part of the key owner's account and cross-account access is denied by default.
- ✗
Update the bucket policy to allow the other account to access the object.
Why it's wrong here
Updating only the bucket policy grants the external account s3:GetObject access to the bucket and object, but it does not address KMS authorization for the SSE-KMS-encrypted object. When S3 serves the object, it must call kms:Decrypt to unwrap the data key, and the KMS key policy is the only bucket-owner-side policy that can give an external account permission to do so. Since the default key policy only delegates authority to the key owner's account, the external principal will receive a KMS AccessDenied error even though the S3 GET is permitted.
- ✗
Update the KMS key policy to allow the other account to decrypt.
Why it's wrong here
Granting kms:Decrypt in the KMS key policy alone fixes the cryptographic layer, but the external account still has no S3 data-plane authorization because cross-account bucket access is denied by default. The bucket policy must also contain an explicit Allow for the external principal to perform s3:GetObject on the specific object (or bucket), and that external IAM user/role must have its own permissions for both actions. A key policy permission only matters if the principal can first reach the object in S3, so the missing bucket policy leaves the operation with an S3 AccessDenied.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.