passdrill
AWS SAA-C03 · IAM & Security · Card 010/014 hard

An IAM role in Account A has an identity-based policy that allows kms:Decrypt on a specific customer managed KMS key that lives in Account B, naming the correct key ARN. The role attempts to decrypt data with that key and is denied. What is the most likely missing piece?

  1. Identity-based policies are ignored entirely whenever the target KMS key belongs to a different account
  2. The role's identity-based policy must instead be rewritten as a service control policy
  3. KMS keys do not support cross-account access under any configuration
  4. The KMS key's own key policy in Account B must also explicitly allow the Account A role to use the key; for KMS, both the identity-based policy and the key policy must authorize the action
Next card → Shuffle