SCS-C02 Data Protection Practice Question
Network Topology
Refer to the exhibit. A security engineer runs the AWS CLI command shown and receives an AccessDenied error. The IAM user Alice has a policy that grants kms:Decrypt on all resources. What is the most likely cause of the error?
⚠ Common exam trap
SCS-C02 often tests the KMS dual-authorization requirement; candidates assume an IAM allow is sufficient and forget that the key policy must also grant access, which is the classic cause of AccessDenied on kms:Decrypt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The KMS key policy does not grant kms:Decrypt to the IAM user Alice.
AWS KMS enforces a two-part authorization model: the caller must be allowed by both the identity-based IAM policy and the KMS key policy. Even though Alice's IAM policy grants kms:Decrypt on all resources, the key policy must also grant her (or her account with delegation) access to that key. If the key policy does not permit Alice, the request is denied, which is the most likely cause of the AccessDenied error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The KMS key policy does not grant kms:Decrypt to the IAM user Alice.
Why this is correct
KMS authorises access through both the key policy and IAM policies. If the key policy does not grant kms:Decrypt to Alice, the request is denied regardless of her identity-based policy, making the key policy the most likely cause.
- ✗
The IAM user policy does not allow kms:Decrypt.
Why it's wrong here
The stem states Alice's policy already grants kms:Decrypt on all resources, so a missing identity permission cannot be the cause; the denial must originate elsewhere, such as a KMS key policy or an explicit Deny. It is tempting because identity policies commonly cause AccessDenied, but here that grant is given.
- ✗
The command uses the wrong key ID.
Why it's wrong here
A wrong key ID would return NotFoundException or InvalidArn, not AccessDenied, so the policy grant on all resources would still apply. It tempts because mistyped identifiers do cause CLI failures, and correcting the ARN is the right fix when the error names a missing key.
- ✗
The ciphertext blob is corrupted.
Why it's wrong here
A corrupted ciphertext blob would typically produce a decryption or InvalidCiphertext failure rather than an authorisation AccessDenied, since KMS rejects the request before evaluating permissions. It is tempting because the CLI command operates on ciphertext, but corruption is a data-integrity fault. AccessDenied points to a policy or key-policy restriction.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.