DVA-C02 Security Practice Question
A developer is troubleshooting access to an Amazon S3 bucket. The bucket policy allows access to the developer's IAM role, but the developer receives an Access Denied error when trying to upload objects. The developer is using an IAM user with access keys for API calls. What is the most likely cause?
⚠ Common exam trap
DVA-C02 often tests the confusion between IAM users and IAM roles as principals, tricking candidates into picking permission-related answers when the real issue is identity mismatch.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The bucket policy allows the role ARN, but the developer is using user credentials
The bucket policy grants access to the developer's IAM role ARN, but the developer is authenticating as an IAM user with access keys. IAM roles and IAM users are distinct principals, so the role-based grant in the bucket policy does not apply to the user's credentials, resulting in Access Denied. The fix is either to assume the role or to add the IAM user ARN to the bucket policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The developer’s IAM user does not have s3:PutObject permission
Why it's wrong here
This option suggests the IAM user's attached policy lacks the s3:PutObject permission. While an Access Denied error would certainly occur in this situation, the scenario implies a troubleshooting context where a bucket policy is also in play. Even if the user's IAM policy did grant the permission, access would still be denied if the S3 bucket policy did not explicitly allow that specific user, or a role/group the user belongs to, to perform the PutObject action. S3 access requires permissions from both the identity and resource policies.
- ✗
The bucket policy does not include a Principal element
Why it's wrong here
An S3 bucket policy is a resource-based policy that explicitly defines permissions for principals on the bucket. Each statement within an S3 bucket policy must include a Principal element to specify the AWS account, IAM user, or IAM role that is allowed or denied access. Omitting the Principal element would render the policy statement syntactically invalid, preventing it from being saved or effectively applied. Consequently, no permissions would be granted by that statement, leading to an Access Denied error for any attempted action.
- ✗
The S3 bucket is in a different region from the developer's API endpoint
Why it's wrong here
Amazon S3 buckets are fundamentally regional resources, meaning they exist within a specific AWS region. When a developer attempts to access an S3 bucket using an API endpoint or SDK configured for a different region than where the bucket resides, S3 typically responds with an HTTP 301 Moved Permanently redirect. This error instructs the client to retry the request against the correct regional endpoint. An Access Denied error, conversely, indicates that the request successfully reached the bucket's correct region but was explicitly rejected due to insufficient authorization.
- ✓
The bucket policy allows the role ARN, but the developer is using user credentials
Why this is correct
This is the most direct cause for an Access Denied error in this scenario. If an S3 bucket policy is configured to grant permissions specifically to an IAM Role's Amazon Resource Name (ARN), but the developer is making the request directly with their personal IAM User credentials, the bucket policy will not recognize the user as the authorized principal. The IAM User and the IAM Role are distinct identities; therefore, the bucket policy's permissions, which are scoped to the role, will not apply to the user, resulting in access being denied.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.