AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard
A security architect needs to grant a partner AWS account direct decrypt access to objects encrypted with a customer managed KMS key, without adding that partner account's IAM users into the key owner's account. Where must this cross-account permission be defined?
- AIn a CloudTrail trail configuration
- BIn an S3 bucket policy only
- CIn the KMS key policy of the key owner's account
- DIn an IAM group policy in the partner account
Show answer & explanationAnswer & explanation
Correct answer: C. In the KMS key policy of the key owner's account
KMS key policies are resource-based policies attached directly to the key and are the only mechanism that governs access to a KMS key from outside the key owner's account. To grant cross-account access, the key policy must explicitly allow the external account, which can then delegate use of the key to its own IAM principals via IAM policies. A bucket policy alone cannot grant decrypt permission on a KMS key.
Why the other options are wrong
- A. CloudTrail records API activity; it does not control access permissions.
- B. S3 bucket policies control S3 object access, not KMS key usage permissions.
- D. An IAM policy in the partner account alone cannot grant access without the key policy also allowing it.
KMS Key Policy
A resource-based policy attached to a KMS key that controls who can use and manage the key, required for cross-account access.
- Every KMS key must have a key policy
- Cross-account access requires both key policy and IAM policy grants
- Default key policy gives full access only to the account root
Memory trick: Key policy is the gatekeeper of the key itself