Question 1 of 30
A financial services company is implementing AWS Key Management Service (KMS) to manage encryption keys for sensitive customer data. They need to ensure that only specific applications can access certain keys while maintaining compliance with regulatory standards. The company decides to use AWS KMS key policies and IAM policies to control access. If the company has a key policy that allows access to a specific IAM role, but the IAM policy attached to that role denies access to the key, what will be the effective permission for that IAM role regarding the KMS key?
The IAM role will be denied access to the KMS key due to the explicit deny in the IAM policy.
The IAM role will have access to the KMS key because the key policy allows it.
The IAM role will have access to the KMS key only if the key policy is modified.
The IAM role will have conditional access to the KMS key based on additional factors.

Preparing for Amazon DVA-C02 AWS Certified Developer – Associate (DVA-C02)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free