SCS-C02 Data Protection Practice Question
Network Topology
Refer to the exhibit. A security engineer is troubleshooting a decryption failure. The command uses the AWS CLI to decrypt a file. The decryption fails with an 'AccessDeniedException' error. The IAM user has the following policy attached:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "kms:Decrypt",
"Resource": "*"
}
]
}What is the most likely cause of the failure?
⚠ Common exam trap
SCS-C02 often tests the KMS dual-authorization model, tricking candidates into assuming that a wildcard IAM policy alone is sufficient — the key policy is the missing piece that causes AccessDeniedException.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The KMS key policy does not grant the IAM user decrypt permission
KMS decryption requires permission from BOTH the IAM identity-based policy AND the KMS key policy. Even though the IAM policy grants kms:Decrypt on '*', the key policy must also explicitly allow the IAM user (or their account with the right conditions) to use the key. If the key policy does not grant access, the request fails with AccessDeniedException regardless of the IAM policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The KMS key policy does not grant the IAM user decrypt permission
Why this is correct
The KMS key policy is the resource policy attached to a KMS key and is the authoritative control for access. In AWS KMS, an IAM policy alone does not grant permission; the key policy must explicitly allow the IAM user (or allow the account's IAM policies to take effect) for kms:Decrypt. Because the key policy here lacks such an allowance, the request is denied with AccessDenied even if the IAM identity policy appears permissive. Therefore, the missing key-policy grant for this user is the direct cause of the failure.
- ✗
The IAM user does not have permission to call kms:Decrypt on the specific key
Why it's wrong here
This explanation incorrectly assumes the IAM user's identity-based policy does not cover the key. However, the IAM policy grants kms:Decrypt on all keys, so the identity-side authorization check is already satisfied. KMS requires both the IAM policy and the key policy to align, and the key policy is the restrictive resource policy that blocks the call. The user does have permission to call kms:Decrypt on the specific key from the IAM perspective; the problem is the key policy's refusal to honor that IAM permission, so this option is not the reason for the error.
- ✗
The ciphertext blob is not valid
Why it's wrong here
An invalid ciphertext blob would not cause an AccessDenied error. If KMS received a malformed ciphertext, it would return a cryptographic exception such as KMSInvalidCiphertextException or InvalidCiphertextException, not an authorization failure. AccessDenied is raised during authorization evaluation, before KMS attempts to validate or decrypt the ciphertext blob. Because the error is a permission problem rather than a data-integrity or format problem, invalid ciphertext cannot be the root cause.
- ✗
The IAM user is not authorized to use the AWS CLI
Why it's wrong here
The AWS CLI is simply a client that sends API requests using the caller's credentials; it does not add its own permission layer. If the IAM user lacked authorization to use the CLI, the attempt would typically fail with missing credentials, misconfigured access keys, or a signing-related error before the request reaches KMS. The AccessDenied response is returned by the KMS service after authentication succeeds, proving the CLI ran with valid credentials and the request reached KMS. Consequently, the denial is specific to KMS key-policy authorization, not to CLI permission.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.