Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 KMS Key Policy Practice Question

A company uses AWS KMS to encrypt data in Amazon S3. The security team wants to ensure that when an object is retrieved, it is automatically decrypted. They have configured the S3 bucket to use SSE-KMS with a customer managed key. However, when a user downloads an object using the AWS CLI, the object is still encrypted. The IAM policy for the user includes kms:Decrypt permission. What is the MOST likely reason for this issue?

⚠ Common exam trap

Candidates often forget that KMS key policies can override IAM permissions. Even with IAM kms:Decrypt, the key policy must explicitly allow the user.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The KMS key policy does not allow the user to decrypt.

The most likely reason is that the KMS key policy does not allow the user to decrypt. Even though the user's IAM policy includes kms:Decrypt, KMS requires that both the IAM policy and the key policy grant permission. Since the key policy is separate, it may not include the user as a principal. Option B is incorrect because SSE-C is not indicated. Option C is incorrect because s3:GetObject is needed but the issue is decryption. Option D is incorrect because encryption context is not required for automatic decryption via S3; S3 manages it transparently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The KMS key policy does not allow the user to decrypt.

    Why this is correct

    With SSE-KMS, S3 invokes kms:Decrypt using the requesting user's credentials every time an encrypted object is read. The KMS key policy is the resource-based policy that controls which principals can use the key; if it does not grant the user (or the user's role) kms:Decrypt, the KMS call is denied even when the user's IAM policy allows s3:GetObject. That denial manifests as an AccessDenied error during object retrieval.

  • ✗

    The user is using SSE-C instead of SSE-KMS.

    Why it's wrong here

    SSE-C and SSE-KMS are two distinct server-side encryption modes; this bucket uses SSE-KMS, so the object is encrypted with an AWS-managed KMS key rather than a customer-provided key. With SSE-C, the user must include a raw key in every request, but that setup is not applicable here and would not cause a KMS authorization failure. The actual issue is the KMS key policy, not an encryption mode mismatch.

  • ✗

    The user does not have s3:GetObject permission.

    Why it's wrong here

    If s3:GetObject were missing, the request would be rejected by S3's bucket policy and IAM authorization before KMS ever processes the call. In this scenario, the failure occurs during the decryption step, which means the user already passed S3's data-plane checks and was able to retrieve the encrypted object. The error is therefore coming from AWS KMS, not from S3.

  • ✗

    The user is not specifying the correct encryption context in the request.

    Why it's wrong here

    For SSE-KMS in Amazon S3, the encryption context is automatically constructed by S3 from the bucket name and object key, and the exact same context is used on both encrypt and decrypt calls. A user cannot supply or alter this encryption context through the S3 GetObject API, so failing to specify one is not the cause. If the encryption context were mismatched, KMS would raise an InvalidCiphertextException, but S3 prevents this by managing the context internally.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.