Courseiva
Data Protection →hardMultiple Choice

SCS-C02 Data Protection Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": {
        "AWS": "arn:aws:iam::123456789012:role/DataAccess"
      },
      "Action": [
        "kms:Decrypt",
        "kms:GenerateDataKey"
      ],
      "Resource": "*",
      "Condition": {
        "StringEquals": {
          "kms:ViaService": "s3.us-east-1.amazonaws.com"
        }
      }
    }
  ]
}
```

Refer to the exhibit. A security engineer configures the above KMS key policy. The DataAccess role is used by an application that runs on EC2 instances in the us-east-1 region. The application needs to read encrypted objects from an S3 bucket in the same region. Which of the following is true about this configuration?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The role can decrypt objects in S3, but cannot use the key outside of S3.

The key policy includes a condition 'kms:ViaService' that restricts use of the key to requests that originate from S3 in us-east-1. The DataAccess role has permissions to call kms:Decrypt and kms:GenerateDataKey. With kms:Decrypt, the role can decrypt objects in S3 (e.g., via S3 GetObject with SSE-KMS). The role can also encrypt objects via S3 PutObject using kms:GenerateDataKey. However, the 'kms:ViaService' condition prevents the role from using the key for any operation outside of S3 (e.g., direct KMS API calls). Option A is incorrect because the condition restricts usage to S3 in us-east-1 only, not any region or any operation. Option B is incorrect because the condition 'kms:ViaService' is syntactically valid and functions as intended. Option C is incorrect because the role has kms:GenerateDataKey, which allows encryption via S3 PutObject, and kms:Decrypt for decryption, so it can both encrypt and decrypt.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The role can use the key for any S3 operation in any region.

    Why it's wrong here

    The role cannot use the key for any S3 operation in any region. The KMS key policy includes a condition that restricts usage to the S3 service in us-east-1 (via kms:ViaService and aws:RequestRegion), and the role's IAM policy only grants kms:Decrypt and kms:GenerateDataKey, not blanket KMS actions. Therefore, even within S3, the role can only perform those two specific cryptographic operations, not 'any' operation. Additionally, using the key with S3 in a different region would fail because the condition enforces us-east-1.

  • ✗

    The role cannot use the key for any operation because the condition is invalid.

    Why it's wrong here

    The condition is not invalid; KMS conditions using kms:ViaService and aws:RequestRegion are standard, supported policy constructs. The condition syntax is correct and KMS will evaluate it properly, so the role's permissions are valid and enforceable. An invalid condition would typically mean a malformed ARN or unsupported condition key, neither of which applies here. Thus, the role does have valid permissions, but only within the scope defined by the condition.

  • ✗

    The role can only encrypt data, not decrypt it.

    Why it's wrong here

    The policy explicitly allows kms:Decrypt and kms:GenerateDataKey, so the role is not restricted to encryption only. The kms:Decrypt action lets the role decrypt ciphertext, including data keys used by S3 for SSE-KMS objects, while kms:GenerateDataKey enables generating new data keys for encryption. If the policy allowed only GenerateDataKey, then 'encrypt only' would be accurate, but the presence of Decrypt means both encryption and decryption are permitted.

  • ✓

    The role can decrypt objects in S3, but cannot use the key outside of S3.

    Why this is correct

    The role can decrypt objects in S3 because the policy grants kms:Decrypt and includes a condition that limits the key's use to the S3 service in us-east-1 (for example, kms:ViaService with s3.us-east-1.amazonaws.com). This allows S3 to use the key to decrypt SSE-KMS-encrypted objects. However, the same condition prevents any other service (such as EC2, Lambda, or EBS) from using the key, even within us-east-1. The role also cannot use the key with S3 in other regions, so the overall scope is exactly S3 in us-east-1 for the allowed actions.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.