Courseiva

DEA-C01 Data Operations and Support Practice Question

A data engineer needs to grant an AWS Lambda function permission to read objects from a specific Amazon S3 bucket. The Lambda function assumes an IAM role. Which policy should the engineer attach to the IAM role to allow the Lambda function to read objects from the bucket?

⚠ Common exam trap

Candidates often confuse the resource ARN requirements for bucket-level versus object-level S3 actions, leading to policies that either do not work or grant excessive permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An IAM policy with s3:GetObject and s3:ListBucket actions, with the resource set to the bucket ARN and objects ARN.

To read objects from S3, the Lambda function requires s3:GetObject on the object ARN and s3:ListBucket on the bucket ARN. This combination allows listing the bucket and retrieving objects. Policies that omit the object ARN for GetObject or include unnecessary write permissions are incorrect. The correct policy follows the principle of least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An IAM policy with s3:PutObject and s3:GetObject actions, with resource set to the bucket ARN and objects ARN.

    Why it's wrong here

    This policy includes s3:PutObject, which grants write access that is not required and violates the principle of least privilege. The scenario only requires read access. While it includes the correct read actions, the extra write permission is unnecessary and could pose a security risk. The policy is over-permissive.

  • ✗

    An IAM policy with s3:ListBucket action and resource set to the objects ARN only.

    Why it's wrong here

    s3:ListBucket is a bucket-level action that must be granted on the bucket ARN, not the objects ARN. Setting the resource to the objects ARN would not allow listing the bucket. Additionally, s3:GetObject is missing, so the function could not read objects. This policy is incorrect.

  • ✓

    An IAM policy with s3:GetObject and s3:ListBucket actions, with the resource set to the bucket ARN and objects ARN.

    Why this is correct

    To read objects from an S3 bucket, the Lambda function needs s3:GetObject on the objects and s3:ListBucket on the bucket. The resource for s3:GetObject should be the object ARN (e.g., arn:aws:s3:::bucket/*) and for s3:ListBucket the bucket ARN (arn:aws:s3:::bucket). This policy grants the necessary permissions correctly.

  • ✗

    An IAM policy with s3:GetObject action and resource set to the bucket ARN only.

    Why it's wrong here

    Setting the resource to the bucket ARN alone is insufficient because s3:GetObject requires the object ARN. Without the object ARN, the policy does not grant permission to read objects. The bucket ARN is used for bucket-level actions like s3:ListBucket. This policy would not allow reading objects.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.