nerdexam
Amazon

SCS-C03 · Question #21

A security engineer needs to control access to data that is encrypted with an AWS Key Management Service (AWS KMS) customer managed key. The security engineer also needs to use additional authenticate

Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #21. The question stem and answer options stay visible for context.

Submitted by kwame.gh· Mar 6, 2026Data Protection

Question

A security engineer needs to control access to data that is encrypted with an AWS Key Management Service (AWS KMS) customer managed key. The security engineer also needs to use additional authenticated data (AAD) to prevent tampering with ciphertext. Which solution will meet these requirements?

Options

  • APass the key alias to AWS KMS when calling the Encrypt and Decrypt API actions.
  • BUse IAM policies to restrict access to the Encrypt and Decrypt API actions.
  • CUse the kms:EncryptionContext condition key when defining IAM policies for the customer
  • DUse key policies to restrict access to the appropriate IAM groups.

Unlock SCS-C03 to see the answer

You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#KMS encryption context#additional authenticated data#IAM condition key#ciphertext integrity
Full SCS-C03 Practice