Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "StringEquals": {
          "s3:x-amz-server-side-encryption": "AES256"
        }
      }
    }
  ]
}

A developer attached the following IAM policy to an IAM user:

```json

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "StringEquals": {

"s3:x-amz-server-side-encryption": "AES256"

}
      }
    }
  ]
}

```

The user tries to download an object from example-bucket using the AWS CLI without specifying server-side encryption. What will happen?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The download fails with an AccessDenied error

The IAM policy allows s3:GetObject only if the request includes server-side encryption set to AES256. Since the user does not specify encryption, the condition is unmet, resulting in an AccessDenied error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The download succeeds because the policy allows s3:GetObject

    Why it's wrong here

    Although the IAM policy statement explicitly lists `s3:GetObject` as an allowed action, this permission is not unconditional. The `Allow` effect for `s3:GetObject` is constrained by a `Condition` block, which acts as an additional gate that must be satisfied for the permission to take effect. Therefore, simply having `s3:GetObject` allowed is insufficient; the request must also meet all specified conditions, such as including the required server-side encryption header, for the download to succeed.

  • ✓

    The download fails with an AccessDenied error

    Why this is correct

    The IAM policy attached to the user explicitly includes a condition requiring the `s3:x-amz-server-side-encryption` header with a specific value in the request for `s3:GetObject` to be allowed. If the user attempts to download the object without including this mandatory header in their request, the policy's condition is not met. Consequently, access is denied, resulting in an `AccessDenied` error, typically an HTTP 403 Forbidden status.

  • ✗

    The download succeeds because the object is encrypted with SSE-S3

    Why it's wrong here

    While the S3 object might be encrypted at rest using SSE-S3 (Server-Side Encryption with S3-managed keys), the IAM policy's condition specifically mandates that the *request itself* must include the `x-amz-server-side-encryption` header. The object's existing encryption state does not automatically satisfy a policy condition that requires the client's download request to explicitly declare server-side encryption. The policy evaluates the attributes of the incoming request, not the object's pre-existing properties, against its conditions.

  • ✗

    The download fails with a 500 Internal Server Error

    Why it's wrong here

    A 500 Internal Server Error indicates an unexpected problem on the server side, such as a service malfunction or an unhandled exception within the AWS S3 service itself. In this scenario, the issue is not a server-side failure but rather a deliberate denial of access based on an unmet condition within the IAM policy. AWS S3 consistently returns an `AccessDenied` error (HTTP 403 Forbidden) when a principal's request fails to satisfy the specified permissions or conditions.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.