nerdexam
Amazon

SCS-C02 · Question #355

Your company has created a set of keys using the AWS KMS service. They need to ensure that each key is only used for certain services. For example , they want one key to be used only for the S3…

The correct answer is C. Use the kms:ViaService condition in the Key policy. Option A and B are invalid because mapping keys to services cannot be done via either the IAM or bucket policy Option D is invalid because keys for IAM users cannot be assigned to services This is mentioned in the AWS Documentation The kms:ViaService condition key limits use of…

Submitted by viktor_hu· Mar 6, 2026Data Protection

Question

Your company has created a set of keys using the AWS KMS service. They need to ensure that each key is only used for certain services. For example , they want one key to be used only for the S3 service. How can this be achieved?

Options

  • ACreate an IAM policy that allows the key to be accessed by only the S3 service.
  • BCreate a bucket policy that allows the key to be accessed by only the S3 service.
  • CUse the kms:ViaService condition in the Key policy
  • DDefine an IAM user, allocate the key and then assign the permissions to the required service

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    83% (20)
  • D
    4% (1)

Explanation

Option A and B are invalid because mapping keys to services cannot be done via either the IAM or bucket policy Option D is invalid because keys for IAM users cannot be assigned to services This is mentioned in the AWS Documentation The kms:ViaService condition key limits use of a customer-managed CMK to requests from particular AWS services. (AWS managed CMKs in your account, such as aws/s3, are always restricted to the AWS service that created them.) For example, you can use kms:V1aService to allow a user to use a customer managed CMK only for requests that Amazon S3 makes on their behalf. Or you can use it to deny the user permission to a CMK when a request on their behalf comes from AWS Lambda.

Topics

#KMS key policy#ViaService condition#service-specific encryption#key management

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice