nerdexam
Amazon

DOP-C02 · Question #254

A company uses an Amazon Elastic Kubernetes Service (Amazon EKS) cluster to deploy its web applications on containers. The web applications contain confidential data that cannot be decrypted without s

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #254. The question stem and answer options stay visible for context.

Submitted by carlos_mx· Mar 6, 2026Security & Compliance

Question

A company uses an Amazon Elastic Kubernetes Service (Amazon EKS) cluster to deploy its web applications on containers. The web applications contain confidential data that cannot be decrypted without specific credentials. A DevOps engineer has stored the credentials in AWS Secrets Manager. The secrets are encrypted by an AWS Key Management Service (AWS KMS) customer managed key. A Kubernetes service account for a third-party tool makes the secrets available to the applications. The service account assumes an IAM role that the company created to access the secrets. The service account receives an Access Denied (403 Forbidden) error while trying to retrieve the secrets from Secrets Manager. What is the root cause of this issue?

Options

  • AThe IAM role that is attached to the EKS cluster does not have access to retrieve the secrets from
  • BThe key policy for the customer managed key does not allow the Kubernetes service account IAM
  • CThe key policy for the customer managed key does not allow the EKS cluster IAM role to use the
  • DThe IAM role that is assumed by the Kubernetes service account does not have permission to

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS Secrets Manager#AWS KMS#KMS Key Policy#IAM Roles for Service Accounts (IRSA)
Full DOP-C02 Practice