Courseiva
Data Security and GovernancehardMultiple ChoiceObjective-mapped

DEA-C01 Data Security and Governance Practice Question

A company has an S3 bucket policy that allows access to a specific IAM role. However, an administrator notices that requests from that role are being denied. The bucket is encrypted with AES-256. What is the MOST likely reason for the denial?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The bucket policy allows access, but the VPC endpoint policy denies the action.

The most likely reason for the denial is that the VPC endpoint policy denies the action. Even if the bucket policy allows access to the IAM role, the VPC endpoint policy can explicitly deny the action, which overrides the bucket policy. Option A is incorrect because AES-256 encryption does not require additional permissions like s3:Decrypt. Option B is incorrect because the question indicates the bucket policy allows access, not denies. Option D is incorrect because S3 Block Public Access settings only apply to public access, not to requests from an IAM role.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The IAM role does not have s3:Decrypt permission on the bucket.

    Why it's wrong here

    AES-256 is server-side encryption and does not require decryption permissions.

  • The bucket policy has an explicit deny statement that overrides the allow.

    Why it's wrong here

    The question states the policy allows access, so an explicit deny would contradict that.

  • The bucket policy allows access, but the VPC endpoint policy denies the action.

    Why this is correct

    A VPC endpoint policy can restrict actions even if the bucket policy allows them.

  • The S3 Block Public Access settings are blocking the request.

    Why it's wrong here

    Block Public Access only affects public access, not IAM role access.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,711 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.