Restore S3 GetObject access by fixing ListBucket, KMS Decrypt, and the gateway-endpoint bucket policy

Answer Correct answer: A, D, E — missing s3:ListBucket, missing kms:Decrypt on the key policy, and a bucket policy not allowing the gateway endpoint block GetObject.

A company has an application that needs to get objects from an Amazon S3 bucket. The application runs on Amazon EC2 instances. All the objects in the S3 bucket are encrypted with an AWS Key Management Service (AWS KMS) customer managed key. The resources in the VPC do not have access to the internet and use a gateway VPC endpoint to access Amazon S3. The company discovers that the application is unable to get objects from the S3 bucket. Which factors could cause this issue? (Choose three.)

  1. The IAM instance profile that is attached to the EC2 instances does not allow the s3:ListBucket action for the S3 bucket. Correct Answer
  2. The IAM instance profile that is attached to the EC2 instances does not allow the s3:ListParts action for the S3 bucket.
  3. The KMS key policy that encrypts the objects in the S3 bucket does not allow the kms:ListKeys action to the EC2 instance profile ARN.
  4. The KMS key policy that encrypts the objects in the S3 bucket does not allow the kms:Decrypt action to the EC2 instance profile ARN. Correct Answer
  5. The S3 bucket policy does not allow access from the gateway VPC endpoint. Correct Answer

Community Votes

ADE
100%

100% of anonymous learners picked answer ADE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Reading a KMS-encrypted object through a gateway endpoint needs three permissions aligned: S3 read/list permission on the instance profile, kms:Decrypt on the CMK key policy for that principal, and a bucket policy that permits the gateway endpoint. ListParts is for multipart uploads and ListKeys is for key enumeration—neither affects GetObject. A, D, E are the failure factors.

An EC2 app reaches S3 only through a gateway VPC endpoint, and objects are KMS-CMK encrypted. Three things can block GetObject: the instance profile lacks s3:ListBucket (needed to enumerate/resolve the objects it fetches), the KMS key policy does not grant kms:Decrypt to the instance profile (required to decrypt the object on read), and the S3 bucket policy does not allow access from the gateway VPC endpoint (so even the endpoint path is denied). s3:ListParts (B) and kms:ListKeys (C) are unrelated to reading objects.

Picking C (missing kms:ListKeys)—ListKeys only lists key IDs and is not required to decrypt an object. Picking B (missing s3:ListParts)—ListParts is for multipart upload completion, irrelevant to reading. The real blockers are ListBucket scope, kms:Decrypt, and the endpoint bucket policy.

Community Discussion (5 comments)

TareDHakim 👍 1 Selected: ADE
A&E are obvious ones, For D. There's a similar scenario described here,
FunkyFresco 👍 1 Selected: ADE
ADE match with the question.
navid1365 👍 2 Selected: ADE
A, D, E are correct
Certified101 👍 2 Selected: ADE
ADE look right
Zek 👍 4
ADE -Agree See similar question https://www.examtopics.com/discussions/amazon/view/87982-exam-aws-certified-security-specialty-topic-1-question-327/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A (missing s3:ListBucket on the instance profile) blocks the app from resolving/listing the objects it needs. D (missing kms:Decrypt on the CMK key policy for the instance profile) blocks decryption of the encrypted object on read. E (bucket policy not allowing the gateway VPC endpoint) denies even the endpoint path to S3. All three independently prevent GetObject success. These are the factors that could cause the failure.

Why the Other Options Are Wrong

B (missing s3:ListParts) applies to multipart upload completion, not object reads, so it does not block GetObject. C (missing kms:ListKeys) only affects enumerating key IDs, not decrypting a specific object—kms:Decrypt is what is needed. A, D, E are the correct set of factors.

Community Comment Notes

Community voted A,D,E (100). Commenters called A and E obvious and noted D (KMS Decrypt on the key policy for the instance profile) as the less-obvious blocker. B and C were excluded as unrelated to reading encrypted objects.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide