DEA-C01 Data Operations and Support Practice Question
A data engineer needs to grant an AWS Lambda function permission to read objects from a specific Amazon S3 bucket. The Lambda function assumes an IAM role. Which policy should the engineer attach to the IAM role to allow the Lambda function to read objects from the bucket?
⚠ Common exam trap
Candidates often confuse the resource ARN requirements for bucket-level versus object-level S3 actions, leading to policies that either do not work or grant excessive permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An IAM policy with s3:GetObject and s3:ListBucket actions, with the resource set to the bucket ARN and objects ARN.
To read objects from S3, the Lambda function requires s3:GetObject on the object ARN and s3:ListBucket on the bucket ARN. This combination allows listing the bucket and retrieving objects. Policies that omit the object ARN for GetObject or include unnecessary write permissions are incorrect. The correct policy follows the principle of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An IAM policy with s3:PutObject and s3:GetObject actions, with resource set to the bucket ARN and objects ARN.
Why it's wrong here
This policy includes s3:PutObject, which grants write access that is not required and violates the principle of least privilege. The scenario only requires read access. While it includes the correct read actions, the extra write permission is unnecessary and could pose a security risk. The policy is over-permissive.
- ✗
An IAM policy with s3:ListBucket action and resource set to the objects ARN only.
Why it's wrong here
s3:ListBucket is a bucket-level action that must be granted on the bucket ARN, not the objects ARN. Setting the resource to the objects ARN would not allow listing the bucket. Additionally, s3:GetObject is missing, so the function could not read objects. This policy is incorrect.
- ✓
An IAM policy with s3:GetObject and s3:ListBucket actions, with the resource set to the bucket ARN and objects ARN.
Why this is correct
To read objects from an S3 bucket, the Lambda function needs s3:GetObject on the objects and s3:ListBucket on the bucket. The resource for s3:GetObject should be the object ARN (e.g., arn:aws:s3:::bucket/*) and for s3:ListBucket the bucket ARN (arn:aws:s3:::bucket). This policy grants the necessary permissions correctly.
- ✗
An IAM policy with s3:GetObject action and resource set to the bucket ARN only.
Why it's wrong here
Setting the resource to the bucket ARN alone is insufficient because s3:GetObject requires the object ARN. Without the object ARN, the policy does not grant permission to read objects. The bucket ARN is used for bucket-level actions like s3:ListBucket. This policy would not allow reading objects.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.