SOA-C02 Security and Compliance Practice Question
A company wants to ensure that only specific IAM roles within the same AWS account can encrypt and decrypt data using an AWS KMS customer managed key. Which type of policy must be configured to achieve this restriction?
⚠ Common exam trap
Many exam-takers think an IAM policy alone is sufficient to grant KMS key access, but they forget that KMS key policies act as a resource-based policy that must explicitly allow the IAM principal, otherwise the IAM policy is ignored.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
KMS key policy
A KMS key policy is the primary mechanism to control access to a customer managed key. By default, a KMS key policy must explicitly grant the necessary permissions (kms:Encrypt, kms:Decrypt) to IAM roles, and it can restrict those permissions to specific roles within the same account using the `aws:PrincipalArn` condition key. This ensures that only the designated IAM roles can encrypt and decrypt data with that key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IAM policy attached to the roles
Why it's wrong here
An IAM policy attached to the roles is insufficient by itself because KMS uses a resource-based key policy to control access. Even if a role has an IAM policy allowing kms:Decrypt, the key policy must explicitly permit that role (or allow the account root to delegate permissions) for the permission to take effect. Without such a statement in the key policy, the IAM policy cannot grant any KMS usage.
- ✓
KMS key policy
Why this is correct
A KMS key policy is the resource-based policy attached directly to the customer master key (CMK) that defines which principals can use the key. For roles within the same AWS account, you can either specify the role ARNs directly in the key policy or allow the account root to delegate permissions via IAM policies. This is the authoritative mechanism to restrict key usage to only the designated IAM roles.
- ✗
Service control policy (SCP)
Why it's wrong here
A service control policy (SCP) operates at the AWS Organizations level and applies to all principals within an account or organizational unit. SCPs can only restrict the maximum available permissions; they cannot grant specific permissions to a KMS key. Moreover, an SCP does not have the granularity to target a particular KMS key or individual IAM role, making it unsuitable for this requirement.
- ✗
Resource policy attached to the KMS key
Why it's wrong here
Although a key policy is technically a type of resource policy, AWS specifically refers to the policy attached to a KMS key as a key policy, not a resource policy. Services like S3 or SNS use resource policies, but KMS has its own key policy format and does not accept an additional resource policy attachment. The correct, unambiguous way to grant access to a KMS key is by editing its key policy, not by attaching a separate resource policy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.