nerdexam
Amazon

SCS-C02 · Question #236

A company's engineering team is developing a new application that creates AWS Key Management Service (AWS KMS) customer managed key grants tor users. Immediately after a grant is created, users must b

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #236. The question stem and answer options stay visible for context.

Submitted by viktor_hu· Mar 6, 2026Data Protection

Question

A company's engineering team is developing a new application that creates AWS Key Management Service (AWS KMS) customer managed key grants tor users. Immediately after a grant is created, users must be able to use the KMS key to encrypt a 512-byte payload. During load testing. AccessDeniedException errors occur occasionally when a user first attempts to use the key to encrypt. Which solution should the company's security specialist recommend to eliminate these AccessDeniedException errors?

Options

  • AInstruct users to implement a retry mechanism every 2 minutes until the call succeeds.
  • BInstruct the engineering team to consume a random grant token from users and to call the
  • CInstruct the engineering team to create a random name for the grant when calling the
  • DInstruct the engineering team to pass the grant token returned in the CreateGrant response to

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#KMS grants#grant token#eventual consistency#CreateGrant
Full SCS-C02 Practice