SCS-C02 Identity and Access Management Practice Question
Exhibit
Refer to the exhibit.
```
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::111122223333:root"
},
"Action": "kms:Decrypt",
"Resource": "*",
"Condition": {
"StringEquals": {
"kms:ViaService": "s3.us-east-1.amazonaws.com"
}
}
}
]
}
```Refer to the exhibit. A KMS key policy allows decryption only when the request comes through S3 in us-east-1. An application in account 111122223333 tries to decrypt an S3 object using the KMS key directly via the KMS API (not through S3). What will happen?
⚠ Common exam trap
SCS-C02 often tests the kms:ViaService condition and candidates may assume that having kms:Decrypt permission is enough, forgetting that the condition must be satisfied.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The decryption fails because the condition on kms:ViaService is not satisfied.
The KMS key policy includes a condition that restricts decryption to requests that come through S3 in us-east-1, using the kms:ViaService condition key. When the application calls the KMS Decrypt API directly (not through S3), the kms:ViaService condition is not satisfied, so the request is denied. This is the intended behavior of the policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The decryption succeeds because the principal is the root user.
Why it's wrong here
Although the key policy names the root user as principal, that principal is not exempt from the listed conditions. In KMS, the root user identity is granted permissions only when every condition in the Allow statement evaluates to true. A decryption request that does not arrive through the S3 endpoint fails the kms:ViaService condition even though the principal is technically permitted. Thus root-user status alone does not make the operation succeed.
- ✗
The decryption fails because the policy is invalid.
Why it's wrong here
The policy is not invalid: KMS key policies support statements containing a Principal, Action, Resource, and Condition, and this one is syntactically and semantically valid. An invalid policy would be rejected when saved or might cause a malformed statement error. Instead, the policy exists and grants an Allow, but the Allow is scoped by kms:ViaService. The failure is a policy evaluation result, not a policy-format problem.
- ✗
The decryption succeeds because the principal is allowed.
Why it's wrong here
The Allow statement does name the principal, but an Allow with a Condition grants permission only when all condition keys match the request context. The kms:ViaService key is set by KMS based on the AWS service endpoint through which the call arrives. If the request is a direct KMS Decrypt call, the value is not S3 and the Allow does not apply. Therefore the principal being allowed is insufficient when its allowed action is conditionally restricted.
- ✓
The decryption fails because the condition on kms:ViaService is not satisfied.
Why this is correct
The key policy's Allow for kms:Decrypt is explicitly conditioned on kms:ViaService matching the S3 service endpoint, for example s3.us-east-1.amazonaws.com. When the call is made directly to KMS or through any service other than S3, that condition key does not match. Since the condition is false, the Allow is not applied and KMS returns AccessDenied. The decryption therefore fails precisely because the request did not come via Amazon S3.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.