Fix encrypted-S3 AccessDenied by attaching an inline kms:Decrypt policy to the instance role

Answer Correct answer: C — attach an inline policy with kms:Decrypt to the role; AWS managed policies cannot be edited and the failure is KMS decryption.

A developer operations team uses AWS Identity and Access Management (IAM) to manage user permissions. The team created an Amazon EC2 instance profile role that uses an AWS managed ReadOnlyAccess policy. When an application that is running on Amazon EC2 tries to read a file from an encrypted Amazon S3 bucket, the application receives an AccessDenied error. The team administrator has verified that the S3 bucket policy allows everyone in the account to access the S3 bucket. There is no object ACL that is attached to the file. What should the administrator do to fix the IAM access issue?

  1. Edit the ReadOnlyAccess policy to add kms:Decrypt actions
  2. Add the EC2 IAM role as the authorized Principal to the S3 bucket policy
  3. Attach an inline policy with kms:Decrypt permissions to the IAM role Correct Answer
  4. Attach an inline policy with S3:* permissions to the IAM role

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Reading an SSE-KMS encrypted object requires both S3 read permission and kms:Decrypt on the KMS key. ReadOnlyAccess is an AWS managed policy and cannot be modified, so you must add a dedicated inline (or customer managed) policy with kms:Decrypt rather than editing the managed one or widening S3 permissions.

An EC2 instance profile uses the AWS managed ReadOnlyAccess policy and gets AccessDenied reading a file from an encrypted S3 bucket, even though the bucket policy allows the account. The file is SSE-KMS encrypted, so the role also needs kms:Decrypt on the key. AWS managed policies cannot be edited, so the fix is to attach a separate inline policy granting kms:Decrypt to the role.

Choosing to edit the ReadOnlyAccess policy (impossible—AWS managed policies are read-only) or attaching S3:* (wrong service; the failure is KMS decryption, not S3 authorization, and S3:* would be over-permissive).

Community Discussion (6 comments)

IPLogic 👍 1 Selected: C
To resolve the IAM access issue, the administrator should ensure that the IAM role has the necessary permissions to decrypt the encrypted files in the S3 bucket. Since the files are encrypted, the role needs kms:Decrypt permissions to access them. Therefore, the correct answer is C. Attaching an inline policy with kms:Decrypt permissions to the IAM role will allow the application running on the EC2 instance to read the encrypted files from the S3 bucket. Option A is not ideal because editing the AWS managed ReadOnlyAccess policy is not possible. Option B is unnecessary because the S3 bucket policy already allows access. Option D is too broad and grants more permissions than needed, which is not a best practice for security.
aescudero51 👍 2 Selected: C
C is correct.
fibonacciname 👍 2 Selected: C
C is correct, ReadOnlyAccess is a administer policy by AWS, can't edit.
fibonacciname 👍 1 Selected: B
B es correct, ReadOnlyAccess is a administer policy by AWS, can't edit.
Certified101 👍 1 Selected: C
C is correct, cant edit an AWS managed policy. Need to create a new inline policy
Nash101 👍 1
C A. Edit ReadOnlyAccess Policy: Modifying the ReadOnlyAccess policy to include kms:Decrypt actions would grant these permissions to any role or user attached to that policy. This might be more permissive than necessary and could introduce security risks if the policy is used elsewhere. B. Add Role to S3 Bucket Policy: While adding the EC2 instance profile role to the S3 bucket policy would allow access, it bypasses IAM role-based access control and couples the policy directly to the instance role. This approach is less flexible and doesn't leverage the benefits of IAM roles for managing access. D. Attach Policy with S3: Permissions: Granting S3: permissions through an inline policy would provide excessive access to the application. It's essential to follow the principle of least privilege and only grant the necessary kms:Decrypt permissions for the specific KMS key used for encryption.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The bucket policy already allows the account, so the S3 permission is fine; the AccessDenied comes from KMS, because reading an SSE-KMS object requires kms:Decrypt on the key. ReadOnlyAccess is an AWS managed policy and cannot be edited, so the correct action is to attach an inline policy with kms:Decrypt to the instance role, granting exactly the decryption permission needed.

Why the Other Options Are Wrong

A is wrong because AWS managed policies such as ReadOnlyAccess cannot be edited; you cannot add actions to them. B is wrong because the bucket policy already authorizes the account, so adding the role as a principal there does not address the missing KMS permission. D is wrong because the problem is KMS decryption, not S3 authorization, and granting S3:* would be unnecessarily broad.

Community Comment Notes

Community strongly chose C (86 votes). Commenters stressed "ReadOnlyAccess is an admin policy by AWS, can't edit" and that the fix is an inline kms:Decrypt policy. One stray B vote misunderstood the bucket policy as the gap.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide