SCS-C02 Data Protection Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::123456789012:role/AdminRole"
},
"Action": "kms:Decrypt",
"Resource": "*",
"Condition": {
"StringEquals": {
"kms:EncryptionContext:department": "finance"
}
}
}
]
}Refer to the exhibit. An AWS KMS key policy includes the statement shown. The AdminRole tries to decrypt a ciphertext that was encrypted using the same KMS key with encryption context 'department=engineering'. What will happen?
⚠ Common exam trap
Watch out — candidates often assume kms:Decrypt permission alone is sufficient for decryption, overlooking that encryption context conditions in the key policy can override the permission and cause a failure even when the IAM role has the correct action allowed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The decrypt operation fails because the encryption context does not match the condition.
The KMS key policy includes a condition that requires the encryption context to be 'department=finance' for decryption. When the AdminRole attempts to decrypt, the encryption context must match both the encryption context used during encryption and any conditions in the key policy. Since the ciphertext was encrypted with 'department=engineering', the decryption fails because the encryption context does not satisfy the policy condition, even though the role has kms:Decrypt permission.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The decrypt operation succeeds because the role has kms:Decrypt permission.
Why it's wrong here
An IAM policy that grants kms:Decrypt is not sufficient on its own because KMS authorization is the intersection of IAM permissions, the key policy, and grants. Even when the role is allowed to call Decrypt, the key policy's condition must also hold. Here, the key policy requires an encryption context of department=finance, and the request's context does not match, so the effective authorization fails and KMS denies the call.
- ✗
The decrypt operation succeeds because the encryption context is ignored during decryption.
Why it's wrong here
Encryption context is not ignored during decryption; KMS treats it as authenticated data and uses it as an authorization condition. At encryption time, the context is cryptographically bound to the ciphertext, and the same context must be provided on decryption. If it differs, KMS rejects the request both because the authenticated data does not match and because the key policy condition cannot be satisfied, so the context cannot be disregarded.
- ✗
The decrypt operation fails because the policy does not allow kms:Decrypt without matching context.
Why it's wrong here
This statement mischaracterizes the failure. The key policy does allow kms:Decrypt, but only conditionally when the kms:EncryptionContext:department key equals finance. The problem is not that an unconditional Decrypt grant is missing; it is that the condition evaluates to false for the supplied encryption context. KMS therefore denies the operation because the policy's condition is not met, not because the policy fails to mention Decrypt.
- ✓
The decrypt operation fails because the encryption context does not match the condition.
Why this is correct
The key policy scopes kms:Decrypt to calls whose encryption context contains department=finance. The decrypt request supplies a different encryption context, so the kms:EncryptionContext:department condition key does not match. As a result, the condition in the key policy is false and KMS denies the Decrypt operation. This is expected behavior: encryption context conditions are a way to limit key usage to specific data or workloads.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.