DVA-C02 Troubleshooting and Optimization Practice Question
Exhibit
Refer to the exhibit.
```json
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-bucket/*"
},
{
"Effect": "Allow",
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::my-bucket"
}
]
}
```A developer attached the IAM policy above to an IAM user. The user reports being unable to list objects in the bucket 'my-bucket' using the AWS CLI command 'aws s3 ls s3://my-bucket/'. What is the most likely reason?
⚠ Common exam trap
The trap here is that candidates often focus on the `ListBucket` permission and overlook the prerequisite `GetBucketLocation` call, assuming the CLI only needs the list action for the `ls` command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM policy does not include the s3:GetBucketLocation action.
The `aws s3 ls s3://my-bucket/` command requires the `s3:GetBucketLocation` permission to determine the bucket's region before listing its contents. Without this action, the CLI fails with an error like 'An error occurred (AccessDenied) when calling the GetBucketLocation operation', even if `s3:ListBucket` is granted. Option D correctly identifies this missing permission as the root cause.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IAM policy does not allow the s3:GetObject action on the bucket.
Why it's wrong here
The s3:GetObject action is used to retrieve the actual content of an object from an S3 bucket. However, when the goal is merely to list the objects within a bucket, only the metadata of those objects is required, which is provided by the s3:ListBucket action. Therefore, s3:GetObject is not a prerequisite for successfully listing the contents of an S3 bucket.
- ✗
The IAM policy resource for s3:ListBucket should include the bucket and objects.
Why it's wrong here
The s3:ListBucket action specifically grants permission to list the objects and their prefixes within a given S3 bucket. Its Resource element in an IAM policy must target the bucket ARN itself, such as arn:aws:s3:::your-bucket-name, not a wildcard for objects like arn:aws:s3:::your-bucket-name/*. Listing objects is an operation performed *on* the bucket, not on individual objects.
- ✗
The IAM policy is missing the s3:ListAllMyBuckets action.
Why it's wrong here
The s3:ListAllMyBuckets action provides permission to list all S3 buckets owned by the AWS account, which is a global operation. This is distinct from listing the *contents* of a specific bucket. To list objects within a particular bucket, the s3:ListBucket action is required, making s3:ListAllMyBuckets irrelevant for the task of listing objects inside a specified bucket.
- ✓
The IAM policy does not include the s3:GetBucketLocation action.
Why this is correct
The AWS Command Line Interface (CLI) and SDKs often perform an implicit s3:GetBucketLocation API call to determine the region of an S3 bucket. This action is crucial for the client to correctly route subsequent S3 API requests to the appropriate regional endpoint, especially if the region is not explicitly specified in the command or configuration. Without this permission, the CLI or SDK may fail to connect to the bucket, even if s3:ListBucket is allowed.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.