Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company wants to ensure that only specific IAM roles within the same AWS account can encrypt and decrypt data using an AWS KMS customer managed key. Which type of policy must be configured to achieve this restriction?

⚠ Common exam trap

Many exam-takers think an IAM policy alone is sufficient to grant KMS key access, but they forget that KMS key policies act as a resource-based policy that must explicitly allow the IAM principal, otherwise the IAM policy is ignored.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

KMS key policy

A KMS key policy is the primary mechanism to control access to a customer managed key. By default, a KMS key policy must explicitly grant the necessary permissions (kms:Encrypt, kms:Decrypt) to IAM roles, and it can restrict those permissions to specific roles within the same account using the `aws:PrincipalArn` condition key. This ensures that only the designated IAM roles can encrypt and decrypt data with that key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IAM policy attached to the roles

    Why it's wrong here

    An IAM policy attached to the roles is insufficient by itself because KMS uses a resource-based key policy to control access. Even if a role has an IAM policy allowing kms:Decrypt, the key policy must explicitly permit that role (or allow the account root to delegate permissions) for the permission to take effect. Without such a statement in the key policy, the IAM policy cannot grant any KMS usage.

  • ✓

    KMS key policy

    Why this is correct

    A KMS key policy is the resource-based policy attached directly to the customer master key (CMK) that defines which principals can use the key. For roles within the same AWS account, you can either specify the role ARNs directly in the key policy or allow the account root to delegate permissions via IAM policies. This is the authoritative mechanism to restrict key usage to only the designated IAM roles.

  • ✗

    Service control policy (SCP)

    Why it's wrong here

    A service control policy (SCP) operates at the AWS Organizations level and applies to all principals within an account or organizational unit. SCPs can only restrict the maximum available permissions; they cannot grant specific permissions to a KMS key. Moreover, an SCP does not have the granularity to target a particular KMS key or individual IAM role, making it unsuitable for this requirement.

  • ✗

    Resource policy attached to the KMS key

    Why it's wrong here

    Although a key policy is technically a type of resource policy, AWS specifically refers to the policy attached to a KMS key as a key policy, not a resource policy. Services like S3 or SNS use resource policies, but KMS has its own key policy format and does not accept an additional resource policy attachment. The correct, unambiguous way to grant access to a KMS key is by editing its key policy, not by attaching a separate resource policy.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.