DVA-C02 Security Practice Question
A developer is troubleshooting access to an S3 bucket from an EC2 instance. The bucket policy allows s3:GetObject for the instance's IAM role, but the application is still getting access denied errors. What is the MOST likely cause?
⚠ Common exam trap
AWS frequently tests the interaction between S3 permissions and KMS permissions. Remember that if an S3 bucket is encrypted with a customer managed KMS key (SSE-KMS), the caller needs both S3 permissions (s3:GetObject) and KMS permissions (kms:Decrypt) to successfully download the file. Lacking KMS permissions results in an 'Access Denied' error.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The S3 bucket is encrypted with SSE-KMS and the instance does not have kms:Decrypt permissions.
When an S3 bucket is encrypted using SSE-KMS, any entity attempting to retrieve an object (s3:GetObject) must also have permission to decrypt the object using the KMS key (kms:Decrypt). If the IAM role has the correct S3 permissions but lacks the kms:Decrypt permission on the KMS key, AWS S3 will return an 'Access Denied' error. Why other options are incorrect: - A: Security group restrictions on outbound traffic would cause the connection to time out, not return an 'Access Denied' error. - C: Block Public Access settings prevent anonymous/public access, but access via an authorized IAM role is not public access. - D: If the EC2 instance did not have an instance profile associated, the AWS SDK would fail locally with a credentials lookup error (e.g., 'Unable to locate credentials') rather than receiving an 'Access Denied' response from the S3 service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The EC2 instance's security group does not allow outbound traffic to S3.
Why it's wrong here
Security groups operate at the network interface level, controlling inbound and outbound IP traffic for the EC2 instance itself. While an overly restrictive outbound rule could theoretically block all HTTPS traffic, S3 is an AWS service accessed via public endpoints (or VPC endpoints), not a private IP target that security groups are primarily designed to filter for service access. The fundamental mechanism for an EC2 instance to access S3 is through IAM permissions, not network-level filtering specific to the S3 service endpoint.
- ✓
The S3 bucket is encrypted with SSE-KMS and the instance does not have kms:Decrypt permissions.
Why this is correct
While missing `kms:Decrypt` permissions would indeed prevent an EC2 instance from accessing SSE-KMS encrypted S3 objects, this presumes the instance already has an IAM identity and general S3 access permissions. The scenario describes troubleshooting general access, implying a more fundamental issue. Without an instance profile, the EC2 instance cannot assume any IAM role, meaning it would lack *all* permissions, including any necessary KMS permissions, making the instance profile the more foundational problem.
- ✗
The S3 bucket has a block public access setting enabled.
Why it's wrong here
S3 Block Public Access (BPA) settings are designed to prevent public read or write access to S3 buckets and objects, overriding potentially permissive bucket policies or ACLs. However, BPA does not restrict access from authenticated AWS identities, such as an EC2 instance assuming an IAM role. An EC2 instance with the correct IAM role and associated permissions would still be able to access the bucket, as its access is based on IAM authorization, not public access.
- ✗
The EC2 instance does not have an instance profile associated with the IAM role.
Why it's wrong here
For an EC2 instance to assume an IAM role and inherit its associated permissions, the role must be attached to the instance via an instance profile. The instance profile acts as a container for the IAM role, allowing the EC2 instance to retrieve temporary security credentials from its metadata service. Without this crucial association, the EC2 instance has no AWS identity and therefore no permissions to make API calls to AWS services like S3, regardless of any IAM policies attached to the role itself.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.