Courseiva
Data Protection →mediumMultiple Select

SCS-C02 Data Protection Practice Question

A security engineer is configuring AWS KMS key policies for a customer managed key used to encrypt data in multiple AWS services. The engineer needs to allow the key to be used by principals in the same account and by a specific IAM role in another account for cross-account access. Which two statements should be included in the key policy to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is forgetting that cross-account KMS access requires the key policy to explicitly allow the external principal; an IAM policy in the other account alone is insufficient.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A statement that allows the account root user to have full KMS permissions, enabling IAM policies in the account to delegate access to the key.

For same-account access, the key policy must allow the account root user full KMS permissions so that IAM policies can delegate access. For cross-account access, the key policy must explicitly allow the external IAM role to use the key. The external role also needs an IAM policy allowing the KMS actions. These two statements together satisfy the requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A statement that allows AWS services to use the key on behalf of the account, with a condition that the request comes from the same account.

    Why it's wrong here

    This statement is about service principals, not about cross-account IAM roles. The requirement is to allow a specific IAM role in another account. While service principals might be used for some services, this does not address the cross-account role access. Also, the condition restricts to the same account, which would not apply to the external role.

  • ✓

    A statement that allows the account root user to have full KMS permissions, enabling IAM policies in the account to delegate access to the key.

    Why this is correct

    Including a statement that allows the account root user full KMS permissions is the standard way to enable IAM policies in that account to control access to the key. Without this, IAM policies alone cannot grant access. This statement effectively delegates control to IAM for principals in the same account, which is necessary for same-account access.

  • ✗

    A statement that allows all principals in the other account to use the key, with a condition that they have the appropriate IAM permissions.

    Why it's wrong here

    Allowing all principals in the other account is overly permissive and not least privilege. The requirement is to allow a specific IAM role, not the entire account. While a condition might restrict based on IAM permissions, the key policy would still grant access to all principals, which is broader than needed. This does not meet the specific requirement and introduces risk.

  • ✗

    A statement that denies all access to the key except for the account root user, to enforce strict control.

    Why it's wrong here

    A deny statement for all except root would block the cross-account IAM role and any same-account principals, contradicting the requirement to allow access. This is the opposite of what is needed. Such a statement would prevent the key from being used by the intended principals, making it unusable for the required scenarios.

  • ✓

    A statement that allows the specific IAM role in the other account to use the key for cryptographic operations.

    Why this is correct

    For cross-account access, the key policy must explicitly allow the external principal (the IAM role) to use the key. This is because the key policy is the primary access control for KMS keys. The external role also needs an IAM policy allowing the KMS actions, but the key policy must grant access first. This statement meets that requirement.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.