# AWS240 Supplied Failure Cases

Identifiers/events are fictional and redacted. Diagnose; do not execute corrections.

## Case 1: disabled key

- At 09:14 UTC an encrypted-object read returns `DisabledException`.
- Object exists and workload has `s3:GetObject`.
- Key: symmetric encrypt/decrypt, `KeyState=Disabled`, `Enabled=false`.
- At 09:02 an administrator called `DisableKey`; no ticket is linked.
- Existing key policy permits the service path and workload.

Explain owner, safest correction, rollback, and why adding `kms:*` is wrong.

## Case 2: IAM allow, key-policy gap

- Workload receives `AccessDeniedException` on `kms:Decrypt`.
- Caller/key share account and Region; key is enabled.
- IAM allows decrypt on the exact key.
- Key policy names only an administrator. It neither permits the workload nor enables account IAM delegation.
- No SCP, boundary, or endpoint deny was found.

Explain both policy design directions and choose the narrower correction.

## Case 3: wrong certificate Region

- ALB is in `ap-south-1`; listener cannot use selected certificate.
- ACM in `us-east-1`: matching SAN, `ISSUED`, `InUseBy=[]`.
- ACM in `ap-south-1`: no match.
- This is ALB, not CloudFront.

Identify scope failure and contrast CloudFront.

## Case 4: pending DNS validation

- ACM: `PENDING_VALIDATION` for `api.example.invalid`.
- Expected name: `_a1.api.example.invalid`; value: `_b2.acm-validations.aws`.
- Provider stored `_a1.api.example.invalid.example.invalid`.
- Public lookup for expected name: `NXDOMAIN`.
- CAA allows only an unrelated CA.

Separate the proved DNS-name fault from additional CAA risk and define verification.

## Case 5: stale pending rotation

- `AWSCURRENT=v17`, `AWSPENDING=v18`; last success 41 days ago.
- Schedule: 30 days, two-hour UTC window.
- Token `v18`: create completed; set timed out to database; test/finish absent.
- Lambda SG lost egress to database port after a network change.
- Application still authenticates with v17.

Explain why manual promotion is dangerous. Define correction, idempotent retry proof, and refresh test.

## Case 6: SSM allowed, KMS denied

- Workload can describe/get `/prod/orders/db-endpoint` and `/prod/orders/license`.
- Endpoint is `String`; license is advanced `SecureString` with customer key.
- Application decrypt fails with KMS `AccessDeniedException`.
- Key is enabled. Policy allows workload only when `PARAMETER_ARN` matches `/prod/payments/*`.
- Operator retrieved no values.

Identify condition mismatch and propose a path-scoped correction. Explain SSM and KMS gates separately.

## Cross-case questions

1. Map each case to state, policy, Region, DNS, network, or condition.
2. Which owner must approve each correction?
3. Which event/alarm shortens each incident?
4. What end-to-end test remains after control-plane evidence?
5. Which quick fixes increase blast radius or expose data?
