nerdexam
Amazon

SCS-C02 · Question #355

Your company has created a set of keys using the AWS KMS service. They need to ensure that each key is only used for certain services. For example , they want one key to be used only for the S3 servic

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #355. The question stem and answer options stay visible for context.

Submitted by viktor_hu· Mar 6, 2026Data Protection

Question

Your company has created a set of keys using the AWS KMS service. They need to ensure that each key is only used for certain services. For example , they want one key to be used only for the S3 service. How can this be achieved?

Options

  • ACreate an IAM policy that allows the key to be accessed by only the S3 service.
  • BCreate a bucket policy that allows the key to be accessed by only the S3 service.
  • CUse the kms:ViaService condition in the Key policy
  • DDefine an IAM user, allocate the key and then assign the permissions to the required service

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#KMS key policy#ViaService condition#service-specific encryption#key management
Full SCS-C02 Practice