AWS Certified Developer – Associate (DVA-C02)Troubleshooting and MonitoringHard
A developer is using AWS Systems Manager Parameter Store to manage configuration values for an application. The application deployed on an EC2 instance attempts to retrieve a parameter but intermittently receives an `AccessDeniedException`. The EC2 instance's IAM role has `ssm:GetParameter` permission for the specific parameter ARN. What is the MOST likely reason for this intermittent error?
- AThe parameter is encrypted with a KMS key, and the IAM role is missing `kms:Decrypt` permission.
- BThe application is exceeding the API call rate limit for Systems Manager Parameter Store.
- CThe parameter's value is too large, exceeding the maximum size limit for Parameter Store.
- DThe EC2 instance is attempting to retrieve the parameter from a different AWS region.
Show answer & explanationAnswer & explanation
Correct answer: A. The parameter is encrypted with a KMS key, and the IAM role is missing `kms:Decrypt` permission.
An `AccessDeniedException` implies a permissions issue. While `ssm:GetParameter` is granted, if the parameter is encrypted using AWS KMS, the IAM role also needs `kms:Decrypt` permission for the specific KMS key used to encrypt the parameter. Intermittency can occur if some parameters are encrypted and others are not, or if the KMS key policy itself has conditions.
Why the other options are wrong
- B. Exceeding the API call rate limit would result in a `ThrottlingException`, not an `AccessDeniedException`.
- C. Exceeding the parameter size limit would result in a 'ValidationException' or similar error during parameter creation/update, not an `AccessDeniedException` during retrieval.
- D. Retrieving from a different region would typically result in a 'Parameter not found' or 'Invalid parameter' error, or a region-specific endpoint error, not `AccessDeniedException` if `GetParameter` is allowed.
Parameter Store KMS Access
When Systems Manager Parameter Store parameters are encrypted with AWS KMS, the IAM entity accessing them must have `kms:Decrypt` permission on the associated KMS key.
- Separate permission from `ssm:GetParameter`.
- Applies to `SecureString` type parameters.
- KMS key policy can also restrict access.
Memory trick: Parameter Store needs two keys: one for the door, one for the safe.