Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

A developer is troubleshooting access to an Amazon S3 bucket. The bucket policy allows access to the developer's IAM role, but the developer receives an Access Denied error when trying to upload objects. The developer is using an IAM user with access keys for API calls. What is the most likely cause?

⚠ Common exam trap

DVA-C02 often tests the confusion between IAM users and IAM roles as principals, tricking candidates into picking permission-related answers when the real issue is identity mismatch.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The bucket policy allows the role ARN, but the developer is using user credentials

The bucket policy grants access to the developer's IAM role ARN, but the developer is authenticating as an IAM user with access keys. IAM roles and IAM users are distinct principals, so the role-based grant in the bucket policy does not apply to the user's credentials, resulting in Access Denied. The fix is either to assume the role or to add the IAM user ARN to the bucket policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The developer’s IAM user does not have s3:PutObject permission

    Why it's wrong here

    This option suggests the IAM user's attached policy lacks the s3:PutObject permission. While an Access Denied error would certainly occur in this situation, the scenario implies a troubleshooting context where a bucket policy is also in play. Even if the user's IAM policy did grant the permission, access would still be denied if the S3 bucket policy did not explicitly allow that specific user, or a role/group the user belongs to, to perform the PutObject action. S3 access requires permissions from both the identity and resource policies.

  • ✗

    The bucket policy does not include a Principal element

    Why it's wrong here

    An S3 bucket policy is a resource-based policy that explicitly defines permissions for principals on the bucket. Each statement within an S3 bucket policy must include a Principal element to specify the AWS account, IAM user, or IAM role that is allowed or denied access. Omitting the Principal element would render the policy statement syntactically invalid, preventing it from being saved or effectively applied. Consequently, no permissions would be granted by that statement, leading to an Access Denied error for any attempted action.

  • ✗

    The S3 bucket is in a different region from the developer's API endpoint

    Why it's wrong here

    Amazon S3 buckets are fundamentally regional resources, meaning they exist within a specific AWS region. When a developer attempts to access an S3 bucket using an API endpoint or SDK configured for a different region than where the bucket resides, S3 typically responds with an HTTP 301 Moved Permanently redirect. This error instructs the client to retry the request against the correct regional endpoint. An Access Denied error, conversely, indicates that the request successfully reached the bucket's correct region but was explicitly rejected due to insufficient authorization.

  • ✓

    The bucket policy allows the role ARN, but the developer is using user credentials

    Why this is correct

    This is the most direct cause for an Access Denied error in this scenario. If an S3 bucket policy is configured to grant permissions specifically to an IAM Role's Amazon Resource Name (ARN), but the developer is making the request directly with their personal IAM User credentials, the bucket policy will not recognize the user as the authorized principal. The IAM User and the IAM Role are distinct identities; therefore, the bucket policy's permissions, which are scoped to the role, will not apply to the user, resulting in access being denied.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.