SCS-C02 Data Protection Practice Question
Network Topology
Refer to the exhibit. A user named John encrypts a file using the AWS CLI. John then tries to decrypt the file but receives an AccessDenied error. John has full administrator permissions in IAM. What is the most likely cause?
⚠ Common exam trap
SCS-C02 often tests the interaction between IAM policies and KMS key policies; candidates may assume that IAM admin permissions are sufficient for KMS operations, ignoring key policy requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The KMS key policy does not grant John the kms:Decrypt permission.
The most likely cause is that the KMS key policy does not grant John the kms:Decrypt permission. Even though John has full administrator permissions in IAM, KMS key policies are resource-based policies that must explicitly allow the principal to use the key. If the key policy does not grant John decrypt permissions, access is denied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The ciphertext blob is malformed because it was not base64-decoded before decryption.
Why it's wrong here
The AWS CLI and SDK transparently handle the base64 encoding of the KMS ciphertext blob; when calling kms decrypt, you pass the CiphertextBlob parameter as a binary blob, not an encoded string. If the blob were malformed, KMS would return InvalidCiphertextException or a validation error. Instead, the AccessDenied response indicates an authorization failure, not a data formatting problem.
- ✗
John's IAM policy denies the kms:Decrypt action.
Why it's wrong here
John's IAM policy cannot be denying kms:Decrypt because he is an administrator with full permissions—an explicit DENY would need to exist in an IAM policy. KMS authorization is additive between IAM and key policy, but IAM alone does not grant access unless the key policy permits it. Therefore, the failure stems from the resource-based key policy, not an IAM policy denying the action.
- ✓
The KMS key policy does not grant John the kms:Decrypt permission.
Why this is correct
A KMS key policy is a resource-based policy that defines which principals may use that key, and it must explicitly grant the decrypt permission to John. Even with admin IAM permissions, if John isn't listed as a principal in the key policy, AWS KMS denies the decryption call with AccessDenied. The correction is to add John as a principal with kms:Decrypt action in the key policy or configure the key policy to allow IAM policies, then keep his IAM permission.
- ✗
The key ID used for encryption is different from the key used for decryption.
Why it's wrong here
If the key ID used for encryption differed from the key used for decryption, KMS would return an InvalidCiphertextException, a KMSInvalidStateException, or a key-mismatch validation error—not an AccessDenied. The error in the scenario references the same key ID as the resource, indicating the key was authorized to encrypt but not to decrypt. AccessDenied specifically reflects a permissions evaluation failure, not a mismatch in cryptographic material.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.