SCS-C02 Data Protection Practice Question
A security engineer is troubleshooting an issue where an Amazon RDS for MySQL DB instance encrypted at rest with AWS KMS is failing to launch. The error message indicates a KMS access issue. Which IAM role or policy is most likely missing?
⚠ Common exam trap
The trap here is that candidates often focus on KMS key policies or network configurations, but the real issue is the missing service-linked role that grants RDS the service-level permissions to interact with KMS, which is a common oversight in encrypted RDS troubleshooting scenarios.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The AWSServiceRoleForRDS service-linked role is missing
The AWSServiceRoleForRDS service-linked role is required for RDS to call AWS KMS on your behalf to manage encryption keys for encrypted DB instances. If this role is missing, RDS cannot obtain the necessary permissions to decrypt the KMS key during instance launch, resulting in a KMS access error. This role is automatically created the first time you create an RDS resource, but if it was deleted or not present, you must recreate it to resolve the issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The RDS subnet group is in a private subnet without a NAT gateway
Why it's wrong here
The location of the RDS subnet group in a private subnet without a NAT gateway would only affect outbound internet connectivity to the public KMS endpoint. That type of network failure typically causes timeouts or connection errors, not an authorization or access-denied response. In practice, RDS can reach KMS via a VPC endpoint or the AWS managed network, so the subnet and NAT configuration alone cannot produce a KMS permission error. The underlying problem here is a missing IAM service-linked role, not the network path.
- ✗
The DB instance's security group does not allow outbound traffic to KMS
Why it's wrong here
Security groups are stateful and, by default, allow all outbound traffic; moreover, the DB instance's security group controls traffic to the database itself, not the RDS management plane's API calls to KMS. Even when a VPC endpoint is used for KMS, the relevant network policy is on the VPC endpoint's security group, not on the DB instance's group. KMS requests are authenticated via IAM and the service-linked role, not through security group rules, so an outbound security group rule would have no bearing on this failure.
- ✗
The KMS key policy does not grant access to the root account
Why it's wrong here
The root account inherently has full permissions over KMS keys it owns, unless the key policy explicitly contains a deny statement, so a lack of root access is not a plausible explanation. For RDS to use a KMS key for encryption, the key policy must grant permission to the RDS service-linked role or the rds.amazonaws.com service principal, not to the root account. If the service-linked role is missing, there is no RDS-specific principal to authorize, making this option incorrect even though a key policy issue could exist.
- ✓
The AWSServiceRoleForRDS service-linked role is missing
Why this is correct
The AWSServiceRoleForRDS service-linked role is a predefined IAM role that gives RDS the ability to call AWS services, including KMS, on your behalf for tasks such as encrypting and decrypting database storage. When this role is missing, RDS cannot assume it to perform kms:Encrypt, kms:Decrypt, or kms:GenerateDataKey operations, causing failures when you create, modify, or start an encrypted instance. This is the root cause in this scenario; you can verify or create the role with the AWS CLI command aws iam create-service-linked-role --aws-service-name rds.amazonaws.com.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.