DVA-C02 Security Practice Question
A developer is creating a new IAM policy to allow an application to read objects from a specific S3 bucket and write logs to a CloudWatch log group. Which policy statement is correct?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
{"Effect":"Allow","Action":["s3:GetObject","logs:CreateLogStream","logs:PutLogEvents"],"Resource":["arn:aws:s3:::my-bucket/*","arn:aws:logs:us-east-1:123456789012:log-group:MyLogGroup:*"]}
It grants the necessary permissions: s3:GetObject to read objects from the bucket, and logs:CreateLogStream and logs:PutLogEvents to write logs to the CloudWatch log group. The resources are correctly specified: the bucket ARN with a wildcard for objects, and the log group ARN with a wildcard for log streams. Option A is incorrect because it uses ec2:DescribeInstances, which is unrelated to S3 or CloudWatch. Option B is incorrect because it only allows s3:ListBucket on the bucket (listing objects) but not reading them (s3:GetObject), and it does not include CloudWatch actions. Option D is incorrect because it only allows s3:PutObject (writing objects) rather than reading, and lacks CloudWatch permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
{"Effect":"Allow","Action":["ec2:DescribeInstances"],"Resource":"*"}
Why it's wrong here
ec2:DescribeInstances grants read-only visibility into EC2 instance metadata and has nothing to do with retrieving S3 objects or writing CloudWatch Logs entries; including it violates least privilege because it grants a permission the application does not need at all.
- ✗
{"Effect":"Allow","Action":["s3:ListBucket"],"Resource":"arn:aws:s3:::my-bucket/*"}
Why it's wrong here
s3:ListBucket only permits enumerating the keys within a bucket via the bucket-level API and must be scoped to the bucket ARN itself, not an object path with a trailing wildcard; it does not grant the ability to retrieve object content, so it cannot satisfy a 'read objects' requirement on its own.
- ✓
{"Effect":"Allow","Action":["s3:GetObject","logs:CreateLogStream","logs:PutLogEvents"],"Resource":["arn:aws:s3:::my-bucket/*","arn:aws:logs:us-east-1:123456789012:log-group:MyLogGroup:*"]}
Why this is correct
This statement correctly pairs s3:GetObject, which retrieves object content, with logs:CreateLogStream and logs:PutLogEvents, the two actions required to create a log stream and write log events, and scopes each action to its precise resource ARN, satisfying both requirements with least privilege.
- ✗
{"Effect":"Allow","Action":["s3:PutObject"],"Resource":"arn:aws:s3:::my-bucket/*"}
Why it's wrong here
s3:PutObject grants permission to upload or overwrite objects in the bucket, which is a write operation; the requirement is to read objects, so this action is the functional opposite of what the application needs and also omits any CloudWatch Logs permissions entirely.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.