SOA-C02 Security and Compliance Practice Question
A SysOps administrator needs to share an encrypted AMI with a different AWS account. The AMI uses an AWS KMS key (customer managed key) for EBS encryption. What must be done to allow the target account to launch EC2 instances from the AMI?
⚠ Common exam trap
SOA-C02 often tests the misconception that sharing an encrypted AMI is a single-step operation — candidates forget that KMS key policies are a separate authorization layer from AMI launch permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the AMI launch permissions and add the target account as a principal in the KMS key policy with kms:Decrypt permission.
When an AMI is encrypted with a customer managed KMS key, sharing the AMI launch permissions alone is insufficient because the target account cannot decrypt the underlying EBS snapshots without KMS permissions. The key policy must explicitly grant the target account (or its principals) kms:Decrypt (and typically kms:DescribeKey, kms:CreateGrant, kms:ReEncrypt*) so EC2 can use the key on the target account's behalf. Combining the AMI launch permission modification with the KMS key policy grant is what actually enables cross-account launches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Share the underlying EBS snapshot with the target account.
Why it's wrong here
Sharing the underlying EBS snapshot alone fails because an AMI is a distinct resource; the target account needs launch permissions on the specific AMI ID, not just visibility of its underlying snapshots. Moreover, because the EBS snapshot is encrypted with a customer-managed KMS key, the target account also requires kms:Decrypt access to that key via the key policy or a grant; merely sharing the snapshot does not convey that KMS entitlement. Therefore, this action leaves the AMI unusable.
- ✗
Re-encrypt the AMI using a new KMS key that is shared with the target account.
Why it's wrong here
Re-encrypting the AMI under a new KMS key is an unnecessarily complex workaround when the existing key can be made shareable by editing its key policy. To re-encrypt, you would have to create a new key, copy the AMI or create a new snapshot encrypted with that key, and then still share both the new key and the AMI with the target account. This adds cost and operational overhead without providing any security advantage over simply granting kms:Decrypt to the target account on the original key.
- ✓
Modify the AMI launch permissions and add the target account as a principal in the KMS key policy with kms:Decrypt permission.
Why this is correct
This is the correct procedure for sharing an encrypted AMI across accounts. First, you must grant launch permissions on the AMI to the target account, which allows that account to see and launch instances from the AMI. Second, because the EBS snapshots backing the AMI are encrypted with a customer-managed KMS key, you must add the target account (or the IAM role/principal that will launch the instance) as a principal in the KMS key policy with kms:Decrypt permission. Both actions are required; without the KMS permission, instance launch will fail with an error.
- ✗
Modify the AMI launch permissions to include the target account.
Why it's wrong here
Setting only the AMI launch permissions is insufficient when the AMI is encrypted, because the target account still lacks the cryptographic permission to decrypt the EBS snapshots during instance launch. Even though the target account can see and initiate launch, the EC2 service cannot mount the volumes without kms:Decrypt on the customer-managed KMS key that encrypted them. The key policy must be updated to include the target account as a principal with the Decrypt operation.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.