DVA-C02 Security Practice Question
A developer is troubleshooting access to an S3 bucket from an EC2 instance. The instance has an IAM role with a policy that allows s3:GetObject on the bucket. However, the application receives an AccessDenied error. The bucket policy is as follows:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::123456789012:role/AppRole"
},
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-bucket/*"
}
]
}The EC2 instance is using the correct IAM role. What is the most likely cause of the error?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM role attached to the EC2 instance has a different ARN than the one specified in the bucket policy.
The correct answer is B: the IAM role attached to the EC2 instance has a different ARN than the one specified in the bucket policy. In S3, when a bucket policy explicitly names a Principal, the request must come from exactly that principal; if the instance's role ARN differs (for example, a different role name, path, or account), the bucket policy does not grant access and the request is denied even though the identity-based policy allows s3:GetObject. Option A is wrong because SSE-S3 encryption is transparent to clients and does not cause AccessDenied. Option C is wrong because it merely restates that both policies allow the action, which would not produce a denial. Option D is wrong because the shown bucket policy contains no MFA condition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The bucket uses default encryption with SSE-S3, and the application does not support it.
Why it's wrong here
SSE-S3 (Server-Side Encryption with S3-managed keys) is a transparent encryption method where Amazon S3 handles both encryption and decryption using unique keys for each object. The client application does not need to perform any cryptographic operations or provide encryption headers, as S3 manages the entire process seamlessly. Therefore, an application's lack of explicit "support" for SSE-S3 would not result in an AccessDenied error, as S3 decrypts the object before returning it.
- ✓
The IAM role attached to the EC2 instance has a different ARN than the one specified in the bucket policy.
Why this is correct
For an EC2 instance to access an S3 bucket, both the IAM role attached to the instance and the S3 bucket policy must explicitly grant the necessary permissions. If the S3 bucket policy includes a Principal element or a Condition that references a specific IAM role ARN, a mismatch between that ARN and the actual ARN of the role assumed by the EC2 instance will result in an AccessDenied error. This strict ARN matching ensures that only authorized identities can perform actions, even if the IAM role policy itself grants permissions.
- ✗
The IAM role policy allows s3:GetObject, but the bucket policy also must allow it, which it does.
Why it's wrong here
For an identity (like an IAM role) to access an S3 object, both the identity-based policy (attached to the IAM role) and the resource-based policy (the S3 bucket policy) must explicitly allow the requested action, such as s3:GetObject. If the question states that both policies already grant this permission, then the access denial must stem from another factor, as the fundamental "AND" logic of AWS policy evaluation is satisfied in this regard. This scenario eliminates a common permission misconfiguration where one policy grants access but the other denies or is silent.
- ✗
The bucket policy requires MFA, but the application does not provide it.
Why it's wrong here
An S3 bucket policy can enforce Multi-Factor Authentication (MFA) for specific actions by including a Condition element like "aws:MultiFactorAuthPresent": "true". If such a condition were present and the application's request did not include valid MFA context, an AccessDenied error would occur. However, without an explicit MFA condition in the bucket policy, MFA is not required for access, making this a non-issue for the current troubleshooting scenario.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.