Q39
Single choice
An Amazon EC2 instance is denied access to a newly created IAM KMS CMK used for decrypt actions.
The environment has the following configuration:
1. The instance is allowed the kms:Decrypt action in its IAM role for all resources.
The IAM KMS CMK status is set to enabled
2. The instance can communicate with the KMS API using a configured VPC endpoint
What is causing the issue?