AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard

A security architect needs to grant a partner AWS account direct decrypt access to objects encrypted with a customer managed KMS key, without adding that partner account's IAM users into the key owner's account. Where must this cross-account permission be defined?

  1. AIn a CloudTrail trail configuration
  2. BIn an S3 bucket policy only
  3. CIn the KMS key policy of the key owner's account
  4. DIn an IAM group policy in the partner account
Show answer & explanation

Correct answer: C. In the KMS key policy of the key owner's account

KMS key policies are resource-based policies attached directly to the key and are the only mechanism that governs access to a KMS key from outside the key owner's account. To grant cross-account access, the key policy must explicitly allow the external account, which can then delegate use of the key to its own IAM principals via IAM policies. A bucket policy alone cannot grant decrypt permission on a KMS key.

Why the other options are wrong

  • A. CloudTrail records API activity; it does not control access permissions.
  • B. S3 bucket policies control S3 object access, not KMS key usage permissions.
  • D. An IAM policy in the partner account alone cannot grant access without the key policy also allowing it.

KMS Key Policy

A resource-based policy attached to a KMS key that controls who can use and manage the key, required for cross-account access.

  • Every KMS key must have a key policy
  • Cross-account access requires both key policy and IAM policy grants
  • Default key policy gives full access only to the account root

Memory trick: Key policy is the gatekeeper of the key itself

More Security and Compliance questions