AnswerCorrect answer: D — pass the grant token returned by CreateGrant to the encrypt call to bypass KMS eventual consistency.
A company’s engineering team is developing a new application that creates AWS Key Management Service (AWS KMS) customer managed key grants for users. Immediately after a grant is created, users must be able to use the KMS key to encrypt a 512-byte payload. During load testing, AccessDeniedException errors occur occasionally when a user first attempts to use the key to encrypt. Which solution should the company’s security specialist recommend to eliminate these AccessDeniedException errors?
Instruct users to implement a retry mechanism every 2 minutes until the call succeeds.
Instruct the engineering team to consume a random grant token from users and to call the CreateGrant operation by passing the grant token to the operation. Instruct users to use that grant token in their call to encrypt.
Instruct the engineering team to create a random name for the grant when calling the CreateGrant operation. Return the name to the users and instruct them to provide the name as the grant token in the call to encrypt.
Instruct the engineering team to pass the grant token returned in the CreateGrant response to users. Instruct users to use that grant token in their call to encrypt. Correct Answer
Community Votes
D
83%
A
17%
83% of anonymous learners picked answer D.
Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
AWS KMS grants are eventually consistent; a freshly created grant might not be honored on the very next call. The grant token returned by CreateGrant lets the caller use the grant's permissions at once, regardless of propagation delay. Supplying the actual token (not a random or named one) is the correct, designed fix.
A grant created with CreateGrant may not be effective immediately because KMS is eventually consistent, causing intermittent AccessDeniedException on the first encrypt. The CreateGrant response returns a grant token that authorizes the new permissions immediately, before the grant fully propagates. Having users pass that grant token in their encrypt call removes the errors without retry loops.
Implementing a retry-every-2-minutes workaround (option A), which only masks the propagation delay instead of using the purpose-built grant token. Or generating a random grant token or a grant name (options B/C), which are not valid grant tokens and will not authorize the call.
Community Discussion (5 comments)
m_ch333👍 2Selected: D
D. The AWS KMS API follows an eventual consistency model. When you create a grant, the grant might not be effective immediately. To use the permissions in a new grant immediately, use the grant token for the grant. https://docs.aws.amazon.com/kms/latest/developerguide/using-grant-token.html
Pmktechno👍 1Selected: D
Grant Token Usage: When a grant is created, AWS KMS returns a grant token. This token can be used immediately to perform cryptographic operations with the KMS key, even before the grant is fully propagated. Immediate Access: By passing the grant token to the users and instructing them to use it in their encryption calls, you ensure that they can immediately use the KMS key without encountering access issues. This approach addresses the timing issue that causes the AccessDeniedException errors by allowing immediate use of the grant.
IPLogic👍 1Selected: D
The best solution to eliminate the AccessDeniedException errors is D. Instruct the engineering team to pass the grant token returned in the CreateGrant response to users. Instruct users to use that grant token in their call to encrypt.
HappyG👍 1Selected: D
Option A acknowledges the propagation delay but relies on a suboptimal workaround (retries) instead of using the solution designed for this exact issue (grant tokens). Therefore, D is the correct answer as it resolves the problem efficiently and aligns with AWS best practices.
jdx000👍 1Selected: A
A because of propagation delays
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
KMS is eventually consistent, so a new grant might not take effect instantly, producing AccessDeniedException on the first use. CreateGrant returns a grant token that confers the grant's permissions immediately. Passing that returned token to the encrypt call lets users encrypt right away, eliminating the errors cleanly.
Why the Other Options Are Wrong
A relies on retries to wait out propagation—a workaround, not the designed solution. B and C instruct users to use a random grant token or a grant name as the token; only the actual token returned by CreateGrant is valid, so those approaches fail. D is the correct use of the real returned token.
Community Comment Notes
Community favored D (83 votes). Commenters cited the using-grant-token doc: a new grant may not be effective immediately and the returned grant token enables immediate use. A minority picked A, attributing it to propagation delay, but D is the best-practice fix.