SOA-C02 Security and Compliance Practice Question
A company uses AWS KMS to encrypt EBS volumes attached to EC2 instances. The security team wants to ensure that only specific IAM roles can decrypt the volumes. Which configuration meets this requirement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the KMS key policy to allow only specific IAM roles to use kms:Decrypt.
KMS key policies allow you to specify which IAM roles are allowed to use the key for decryption. Option A is wrong because service control policies (SCPs) are used to set permission boundaries across accounts in an organization, but they are not the most direct way to restrict decryption for specific IAM roles; KMS key policies are more appropriate. Option B is wrong because EBS volumes do not have bucket policies; bucket policies apply to S3 buckets. Option D is wrong because instance profiles and policies denying ec2:DetachVolume do not affect decryption permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a service control policy to deny kms:Decrypt for all users.
Why it's wrong here
A service control policy (SCP) is an account-level permission boundary that applies to every IAM principal in the account, including legitimate roles. Denying kms:Decrypt for all users would also block the EC2 service and any authorized administrator from decrypting EBS volumes, effectively breaking the entire encryption workflow. Moreover, SCPs cannot be targeted to specific roles, so they cannot enforce the required role-based restriction.
- ✗
Apply a bucket policy on the EBS snapshot bucket.
Why it's wrong here
EBS snapshots are stored in an AWS-managed S3 bucket that you do not have access to, so you cannot attach a bucket policy to that underlying storage. Bucket policies only govern user-defined S3 buckets and do not control permissions for EBS volumes or their encrypted data. The encryption and decryption of snapshots is governed by the KMS key policy and IAM permissions, not by S3 bucket policies.
- ✓
Modify the KMS key policy to allow only specific IAM roles to use kms:Decrypt.
Why this is correct
Modifying the KMS key policy is correct because KMS uses a key policy to specify which principals can use the key for cryptographic operations like kms:Decrypt. By allowing only specific IAM roles in the key policy, you ensure that only those roles (and any other explicitly authorized principals) can decrypt the EBS volumes and snapshots encrypted with that key. This works in conjunction with IAM policies; the key policy explicitly grants the roles decrypt access, while all other IAM principals are implicitly denied. You can further refine this with conditions such as kms:ViaService to limit decrypt calls to EC2.
- ✗
Attach an instance profile with a policy that denies ec2:DetachVolume.
Why it's wrong here
An instance profile attached to an EC2 instance supplies temporary credentials for that instance to make API calls, but it cannot restrict IAM users or roles from performing kms:Decrypt. Denying ec2:DetachVolume only prevents the volume from being detached from the instance, not from reading data at rest; encrypted data remains protected by KMS and can still be decrypted by any principal with kms:Decrypt permission. This action does not address the core requirement of restricting decryption to specific IAM roles.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.