Fix encrypted-S3 AccessDenied by attaching an inline kms:Decrypt policy to the instance role
A developer operations team uses AWS Identity and Access Management (IAM) to manage user permissions. The team created an Amazon EC2 instance profile role that uses an AWS managed ReadOnlyAccess policy. When an application that is running on Amazon EC2 tries to read a file from an encrypted Amazon S3 bucket, the application receives an AccessDenied error. The team administrator has verified that the S3 bucket policy allows everyone in the account to access the S3 bucket. There is no object ACL that is attached to the file. What should the administrator do to fix the IAM access issue?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Reading an SSE-KMS encrypted object requires both S3 read permission and kms:Decrypt on the KMS key. ReadOnlyAccess is an AWS managed policy and cannot be modified, so you must add a dedicated inline (or customer managed) policy with kms:Decrypt rather than editing the managed one or widening S3 permissions.
An EC2 instance profile uses the AWS managed ReadOnlyAccess policy and gets AccessDenied reading a file from an encrypted S3 bucket, even though the bucket policy allows the account. The file is SSE-KMS encrypted, so the role also needs kms:Decrypt on the key. AWS managed policies cannot be edited, so the fix is to attach a separate inline policy granting kms:Decrypt to the role.
Choosing to edit the ReadOnlyAccess policy (impossible—AWS managed policies are read-only) or attaching S3:* (wrong service; the failure is KMS decryption, not S3 authorization, and S3:* would be over-permissive).
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.