Courseiva

DVA-C02 Development with AWS Services Practice Question

Exhibit

Refer to the exhibit.

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "s3:PutObject",
            "Resource": "arn:aws:s3:::example-bucket/*",
            "Condition": {
                "StringEquals": {
                    "s3:x-amz-server-side-encryption": "AES256"
                }
            }
        }
    ]
}

A developer attaches the IAM policy shown to a user. The user attempts to upload an object to example-bucket using the AWS CLI with the command: `aws s3 cp file.txt s3://example-bucket/`. The upload fails. What is the MOST likely reason?

⚠ Common exam trap

Many candidates assume an upload failure is due to missing `s3:PutObject` permission, overlooking that S3 condition keys (like encryption requirements) can silently deny requests even when the base action is allowed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user did not specify server-side encryption in the request.

The IAM policy shown (not provided in the question but implied by the context) likely includes a condition that requires server-side encryption (e.g., `s3:x-amz-server-side-encryption: AES256`). The `aws s3 cp` command by default does not set the `--sse` flag, so the request lacks the required encryption header, causing S3 to deny the upload with an AccessDenied error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user does not have permission to perform s3:PutObject on the bucket.

    Why it's wrong here

    The IAM policy explicitly grants `s3:PutObject` permission. The `Resource` ARN `arn:aws:s3:::your-bucket-name/*` specifically targets all objects within 'your-bucket-name', allowing the user to upload objects into it. Therefore, the user *does* have permission to perform `s3:PutObject` on objects in the specified bucket, making this statement incorrect.

  • ✗

    The bucket policy overrides the IAM policy and denies the request.

    Why it's wrong here

    Without the actual bucket policy, it is impossible to determine if it contains an explicit deny statement that would override the IAM policy. AWS IAM policy evaluation logic dictates that an explicit deny in any policy (user, group, role, or resource) always takes precedence over an allow. However, since the bucket policy is not provided, we cannot assume it is the cause of a denial.

  • ✗

    The resource ARN does not include the bucket itself.

    Why it's wrong here

    The `Resource` ARN `arn:aws:s3:::your-bucket-name/*` grants permissions on *objects* within the specified S3 bucket, denoted by the `/*` wildcard. It does not encompass the bucket resource itself, which would be `arn:aws:s3:::your-bucket-name` without the wildcard. Actions directly on the bucket, such as deleting it or changing its configuration, would require a separate ARN and corresponding permissions.

  • ✓

    The user did not specify server-side encryption in the request.

    Why this is correct

    The IAM policy includes a `Condition` requiring `s3:x-amz-server-side-encryption` to be `AES256`. This means any `s3:PutObject` request must explicitly include the `x-amz-server-side-encryption` header with the exact value `AES256`. If the user's request omits this specific header or provides a different encryption method, the condition will not be met, and the action will be implicitly denied, causing the upload to fail.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DVA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A developer attaches this IAM policy to a user. The user tries to upload an object to example-bucket without specifying encryption. What will happen?

medium
  • A.The upload succeeds only if the object is smaller than 5 GB.
  • B.The upload succeeds but the object is not encrypted.
  • C.The upload succeeds because S3 default encryption is applied.
  • ✓ D.The upload fails with an access denied error.

Why D: The question stem refers to 'this IAM policy' but does not provide the policy document. We must include the IAM policy in the stem. To align with the explanation, the policy should use 'StringNotEqualsIfExists' so that a missing encryption header triggers the Deny effect.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.