DVA-C02 Security Practice Question
A developer is creating an IAM policy for an Amazon S3 bucket that must allow read access to a specific object only. Which policy element should be used to restrict access to the object?
⚠ Common exam trap
DVA-C02 often tests the confusion between Action and Resource, where candidates mistakenly believe Action restricts the object, when Resource is the element that specifies the target object.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Resource
The Resource element in an IAM policy specifies the object or bucket to which the policy applies. To allow read access to a specific object only, you must specify the object's ARN (e.g., arn:aws:s3:::bucket-name/object-key) in the Resource element. This restricts the policy's effect to that object.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Action
Why it's wrong here
The Action element in an IAM policy defines the specific API operations that are allowed or denied, such as s3:GetObject or s3:PutObject. While crucial for defining what can be done, it does not specify which particular S3 object these operations apply to. Therefore, Action alone cannot restrict access to 'that object only' without a corresponding Resource specification.
- ✗
Condition
Why it's wrong here
The Condition element allows for specifying additional constraints under which a policy statement grants or denies access, such as requiring a specific source IP address or multi-factor authentication. While powerful for refining policy applicability, it does not directly identify the target S3 object itself. Conditions modify when or how an action on a resource is permitted, rather than defining the specific resource being acted upon.
- ✗
Principal
Why it's wrong here
The Principal element identifies the AWS identity (user, role, or account) that is allowed or denied access by the policy. In an IAM policy, it specifies who is making the request and receiving the permissions. It does not, however, define what specific S3 object is being targeted for access restriction, focusing solely on the identity initiating the action.
- ✓
Resource
Why this is correct
The Resource element is precisely where the specific AWS entity or entities that a policy statement applies to are defined. To restrict access to a particular S3 object, its unique Amazon Resource Name (ARN) must be explicitly listed in this field. This directly scopes the policy's permissions to 'that object only,' ensuring fine-grained control over access to individual S3 objects rather than an entire bucket.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.