DEA-C01 IAM Policy Conditions Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::example-bucket/*",
"Condition": {
"StringEquals": {
"s3:x-amz-server-side-encryption": "AES256"
}
}
}
]
}A data engineer applies the following IAM policy to an IAM user:
```json
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::example-bucket/*",
"Condition": {
"StringEquals": {"s3:x-amz-server-side-encryption": "AES256"
}
}
}
]
}```
The user attempts to download an object from the bucket 'example-bucket' that is encrypted with SSE-S3 (AES256). Will the request succeed?
⚠ Common exam trap
The trap is that candidates assume SSE-S3 is transparent and always allows access, overlooking that the IAM policy condition explicitly requires the encryption header in the request. The condition applies to the request, not the object's encryption-at-rest.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No, because the policy requires the encryption to be specified in the request.
The IAM policy includes a condition that requires the request to include the `x-amz-server-side-encryption` header with value `AES256`. Even though the object is encrypted with SSE-S3, the policy condition evaluates the request headers, not the object's encryption state. Since the user does not specify the encryption header in the download request, the condition fails, and the request is denied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Yes, but only if the user also has s3:ListBucket permission.
Why it's wrong here
The condition keys on the request header s3:x-amz-server-side-encryption, which the caller supplies; a plain GetObject sends no such header, so the condition never matches regardless of ListBucket. It is tempting because ListBucket is genuinely needed for console browsing and prefix listing, but object downloads do not require it.
- ✓
No, because the policy requires the encryption to be specified in the request.
Why this is correct
The condition key `s3:x-amz-server-side-encryption` evaluates the request header, not the object's stored encryption state. SSE-S3 encrypts objects automatically without requiring that header, so a plain GetObject request carries no matching key and the condition fails. The download is denied despite the object being AES256-encrypted.
- ✗
Yes, because the object is encrypted with SSE-S3 which uses AES256.
Why it's wrong here
The condition tests the request header s3:x-amz-server-side-encryption, not the object's stored encryption, so a default GetObject without that header fails the StringEquals check even though the object uses AES256. It is tempting because SSE-S3 does use AES256, but that describes the object, not the request.
- ✗
No, because the policy does not allow the s3:GetObject action for encrypted objects.
Why it's wrong here
The condition merely requires that requests specify AES256 server-side encryption; it does not deny access to encrypted objects, and SSE-S3 objects satisfy it, so the download succeeds. The option is tempting because conditions can restrict actions, but here the StringEquals check matches rather than blocks.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,321-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DEA-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A data engineer attaches the above IAM policy to an IAM user. The user tries to download an object from my-bucket using the AWS CLI without specifying SSE headers. The object is stored with SSE-S3. Will the download succeed?
hard- A.No, because the object is encrypted and the user does not have decrypt permission.
- B.No, because the request does not include the required encryption header.
- C.Yes, because the object is encrypted with SSE-S3, which uses AES256.
- ✓ D.Yes, because the policy allows s3:GetObject on the bucket.
Why D: For SSE-S3 objects, no additional encryption headers are required on GET requests because S3 handles decryption transparently for authorized users. The IAM policy grants s3:GetObject, so the download succeeds.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.