Courseiva
Data Operations and SupporthardMultiple ChoiceObjective-mapped

DEA-C01 Data Operations and Support Practice Question

Exhibit

Refer to the exhibit.

```
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "s3:GetObject",
                "s3:PutObject",
                "s3:DeleteObject"
            ],
            "Resource": "arn:aws:s3:::data-bucket/*"
        },
        {
            "Effect": "Allow",
            "Action": [
                "s3:ListBucket"
            ],
            "Resource": "arn:aws:s3:::data-bucket"
        },
        {
            "Effect": "Deny",
            "Action": "s3:*",
            "Resource": "arn:aws:s3:::data-bucket/confidential/*",
            "Condition": {
                "StringNotEquals": {
                    "aws:PrincipalTag/role": "admin"
                }
            }
        }
    ]
}
```

Refer to the exhibit. This IAM policy is attached to a user who is trying to read the object s3://data-bucket/confidential/report.csv. The user's principal tag 'role' is set to 'analyst'. What will happen when the user attempts to read the object?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Denied because the condition in the Deny statement evaluates to true

The Deny statement applies when the role tag is not 'admin'. The user's tag is 'analyst', so the condition matches and access is denied. Option A is wrong because the Allow statement is overridden by the explicit Deny. Option B is wrong because the Deny applies to all actions in the confidential prefix. Option D is wrong because Deny overrides Allow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Denied because the Deny statement covers all actions under confidential

    Why it's wrong here

    The Deny condition checks the tag; the condition matches, so Deny applies.

  • Allowed because there is an explicit Allow and no explicit Deny that matches

    Why it's wrong here

    Explicit Deny exists and matches.

  • Denied because the condition in the Deny statement evaluates to true

    Why this is correct

    The condition StringNotEquals 'admin' is true for 'analyst', so Deny is applied.

  • Allowed because of the Allow statement for s3:GetObject

    Why it's wrong here

    Explicit Deny overrides Allow.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DEA-C01 question is part of Courseiva's 1,711-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on DEA-C01

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A data engineer has attached the IAM policy shown in the exhibit to a role used by an AWS Glue ETL job. The job fails when trying to write to the S3 bucket 'example-bucket' with the error: 'Access Denied'. What is the MOST likely reason?

hard
  • A.The IAM policy does not include the bucket ARN for write operations.
  • B.The IAM role's trust policy does not allow Glue to assume the role.
  • C.The S3 bucket policy denies the PutObject action for the role.
  • D.The IAM policy does not grant s3:PutObject permission.

Why C: Even if the IAM policy allows s3:PutObject on the bucket, the S3 bucket policy can explicitly deny the action for the role, resulting in 'Access Denied'. The exhibit shows the IAM policy grants s3:PutObject, so the error must stem from the bucket policy. Option A is incorrect because the IAM policy does include the bucket ARN for write operations. Option B is incorrect because a trust policy failure would prevent role assumption and produce a different error, not an S3 access denied. Option D is incorrect because the IAM policy does grant s3:PutObject permission.

Variation 2. Refer to the exhibit. An IAM policy is attached to a user who needs to read objects from the 'example-bucket' S3 bucket. The user reports being unable to read any object under the 'confidential/' prefix. What is the reason for this access issue?

medium
  • A.The allow statement is evaluated before the deny statement
  • B.The deny statement is missing an explicit allow for the confidential prefix
  • C.The explicit deny statement overrides the allow statement
  • D.The resource ARN in the deny statement is incorrect

Why C: An explicit deny statement overrides any allow statement, regardless of the order in which they appear. In this policy, there is an allow for GetObject on all objects in example-bucket, but there is an explicit deny for GetObject on the 'confidential/' prefix. Since explicit deny takes precedence, the user cannot read objects under that prefix. Option A is incorrect because the order of evaluation does not matter; explicit deny always wins. Option B is incorrect because the deny statement does not need an explicit allow; the deny itself is effective. Option D is incorrect because the resource ARN in the deny statement is correctly specified as 'arn:aws:s3:::example-bucket/confidential/*'.

Variation 3. Refer to the exhibit. An IAM policy is attached to an IAM user. The user is trying to upload an object to 's3://data-lake-bucket/confidential/report.pdf' using the AWS CLI. The upload fails with an AccessDenied error. What is the reason for the failure?

hard
  • A.The policy does not include 's3:PutObject' action.
  • B.The resource ARN in the Allow statement does not cover the specific object.
  • C.The user does not have permission to access the bucket at all.
  • D.An explicit Deny statement overrides the Allow statement for the 'confidential/' prefix.

Why D: The IAM policy includes an explicit Deny statement that denies all s3 actions on the 'confidential/' prefix. Even though there is an Allow statement that grants s3:PutObject on the bucket, the explicit Deny overrides it, causing the upload to fail with AccessDenied. Option A is incorrect because the policy does include the s3:PutObject action. Option B is incorrect because the resource ARN in the Allow statement covers the bucket and objects, but the Deny specifically targets 'confidential/'. Option C is incorrect because the user does have permission to access the bucket via the Allow statement, but the Deny blocks access to the specific object under 'confidential/'.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.