A company is designing a data protection strategy for its Amazon S3 bucket that stores sensitive customer data. The bucket must be encrypted at rest using a customer managed key (CMK) that is stored in AWS KMS. The company also needs to ensure that only authorized users can decrypt objects. Which TWO actions should the company take?
Modifying the KMS key policy is the correct approach because the key policy is the resource-based policy that directly controls which principals can call kms:Decrypt on the CMK. By explicitly listing only authorized IAM roles as principals with Decrypt permission, you ensure that even if an S3 bucket policy or object ACL grants read access to ciphertext, those roles cannot decrypt it without the key. This is a robust data protection strategy because it combines S3 access control with KMS key-level authorization.
Why this answer
Option B is correct because the KMS key policy is the primary resource-based access control for a customer managed key, so modifying it to allow only the authorized IAM roles to use the key ensures that no other principals can call kms:Decrypt or otherwise use the CMK to access the encrypted S3 objects. Option C is correct because even if the key policy permits a role, the caller still needs an identity-based IAM policy granting kms:Decrypt on that specific CMK, so attaching such a policy to the authorized users is required for them to decrypt the objects. Together, the key policy and the IAM policy satisfy the requirement that only authorized users can decrypt data encrypted with the CMK.
Option A does not belong because S3 server-side encryption with KMS does not use encryption context in the s3:GetObject request in the way described, and denying based on encryption context is not the mechanism for restricting decryption to authorized users. Option D does not belong because a VPC endpoint and bucket policy control network/API access to S3, not who can decrypt with the KMS CMK. Option E does not belong because SSE-C uses a customer-provided key rather than a CMK stored in AWS KMS, which contradicts the stated requirement.
Exam trap
SCS-C02 often tests the dual requirement of KMS key policies and IAM policies — candidates may pick only one, forgetting that both must allow the action for access to be granted.