DEA-C01 Data Operations and Support Practice Question
Exhibit
Refer to the exhibit.
```
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:PutObject",
"s3:DeleteObject"
],
"Resource": "arn:aws:s3:::data-bucket/*"
},
{
"Effect": "Allow",
"Action": [
"s3:ListBucket"
],
"Resource": "arn:aws:s3:::data-bucket"
},
{
"Effect": "Deny",
"Action": "s3:*",
"Resource": "arn:aws:s3:::data-bucket/confidential/*",
"Condition": {
"StringNotEquals": {
"aws:PrincipalTag/role": "admin"
}
}
}
]
}
```Refer to the exhibit. This IAM policy is attached to a user who is trying to read the object s3://data-bucket/confidential/report.csv. The user's principal tag 'role' is set to 'analyst'. What will happen when the user attempts to read the object?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Denied because the condition in the Deny statement evaluates to true
The Deny statement applies when the role tag is not 'admin'. The user's tag is 'analyst', so the condition matches and access is denied. Option A is wrong because the Allow statement is overridden by the explicit Deny. Option B is wrong because the Deny applies to all actions in the confidential prefix. Option D is wrong because Deny overrides Allow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Denied because the Deny statement covers all actions under confidential
Why it's wrong here
The Deny condition checks the tag; the condition matches, so Deny applies.
- ✗
Allowed because there is an explicit Allow and no explicit Deny that matches
Why it's wrong here
Explicit Deny exists and matches.
- ✓
Denied because the condition in the Deny statement evaluates to true
Why this is correct
The condition StringNotEquals 'admin' is true for 'analyst', so Deny is applied.
- ✗
Allowed because of the Allow statement for s3:GetObject
Why it's wrong here
Explicit Deny overrides Allow.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DEA-C01 question is part of Courseiva's 1,711-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on DEA-C01
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A data engineer has attached the IAM policy shown in the exhibit to a role used by an AWS Glue ETL job. The job fails when trying to write to the S3 bucket 'example-bucket' with the error: 'Access Denied'. What is the MOST likely reason?
hard- A.The IAM policy does not include the bucket ARN for write operations.
- B.The IAM role's trust policy does not allow Glue to assume the role.
- ✓ C.The S3 bucket policy denies the PutObject action for the role.
- D.The IAM policy does not grant s3:PutObject permission.
Why C: Even if the IAM policy allows s3:PutObject on the bucket, the S3 bucket policy can explicitly deny the action for the role, resulting in 'Access Denied'. The exhibit shows the IAM policy grants s3:PutObject, so the error must stem from the bucket policy. Option A is incorrect because the IAM policy does include the bucket ARN for write operations. Option B is incorrect because a trust policy failure would prevent role assumption and produce a different error, not an S3 access denied. Option D is incorrect because the IAM policy does grant s3:PutObject permission.
Variation 2. Refer to the exhibit. An IAM policy is attached to a user who needs to read objects from the 'example-bucket' S3 bucket. The user reports being unable to read any object under the 'confidential/' prefix. What is the reason for this access issue?
medium- A.The allow statement is evaluated before the deny statement
- B.The deny statement is missing an explicit allow for the confidential prefix
- ✓ C.The explicit deny statement overrides the allow statement
- D.The resource ARN in the deny statement is incorrect
Why C: An explicit deny statement overrides any allow statement, regardless of the order in which they appear. In this policy, there is an allow for GetObject on all objects in example-bucket, but there is an explicit deny for GetObject on the 'confidential/' prefix. Since explicit deny takes precedence, the user cannot read objects under that prefix. Option A is incorrect because the order of evaluation does not matter; explicit deny always wins. Option B is incorrect because the deny statement does not need an explicit allow; the deny itself is effective. Option D is incorrect because the resource ARN in the deny statement is correctly specified as 'arn:aws:s3:::example-bucket/confidential/*'.
Variation 3. Refer to the exhibit. An IAM policy is attached to an IAM user. The user is trying to upload an object to 's3://data-lake-bucket/confidential/report.pdf' using the AWS CLI. The upload fails with an AccessDenied error. What is the reason for the failure?
hard- A.The policy does not include 's3:PutObject' action.
- B.The resource ARN in the Allow statement does not cover the specific object.
- C.The user does not have permission to access the bucket at all.
- ✓ D.An explicit Deny statement overrides the Allow statement for the 'confidential/' prefix.
Why D: The IAM policy includes an explicit Deny statement that denies all s3 actions on the 'confidential/' prefix. Even though there is an Allow statement that grants s3:PutObject on the bucket, the explicit Deny overrides it, causing the upload to fail with AccessDenied. Option A is incorrect because the policy does include the s3:PutObject action. Option B is incorrect because the resource ARN in the Allow statement covers the bucket and objects, but the Deny specifically targets 'confidential/'. Option C is incorrect because the user does have permission to access the bucket via the Allow statement, but the Deny blocks access to the specific object under 'confidential/'.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.