DVA-C02 Security Practice Question
A developer is troubleshooting an issue where an S3 bucket policy is not granting cross-account access to a user in another AWS account. The bucket policy uses a Principal element with the AWS account ID. What is the most likely reason for the failure?
⚠ Common exam trap
DVA-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access, ignoring the need for the user's IAM policy to also allow the action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM user in the other account does not have an IAM policy that allows the S3 action.
The most likely reason is that the IAM user in the other account does not have an IAM policy that allows the S3 action. For cross-account access, both the bucket policy (resource-based) and the IAM policy (identity-based) must grant the necessary permissions. Even if the bucket policy allows the account, the user's IAM policy must also allow the action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The bucket is encrypted with SSE-S3, which blocks cross-account access.
Why it's wrong here
SSE-S3 encryption manages the encryption and decryption of objects at rest using AWS-managed keys, but it does not inherently control access permissions. Access to S3 objects, regardless of SSE-S3 encryption status, is governed solely by the combination of IAM identity-based policies and S3 bucket policies. As long as the requesting principal has the necessary s3:GetObject or other relevant S3 permissions, S3 transparently handles decryption, making SSE-S3 irrelevant to cross-account access denial.
- ✗
The bucket policy must use the user's ARN instead of the account ID.
Why it's wrong here
A bucket policy can effectively grant permissions to an entire external AWS account by specifying its account ID in the Principal element. This establishes the necessary trust relationship from the resource owner's side, allowing any principal within that external account to potentially access the bucket. However, for a specific IAM user or role within that trusted account to actually perform actions, they must also possess an explicit identity-based IAM policy that grants the corresponding S3 permissions. The account ID in the bucket policy is a valid and common method for cross-account access, not a blocker.
- ✗
The bucket policy cannot grant access to users in another account.
Why it's wrong here
S3 bucket policies are a fundamental and widely used mechanism specifically designed to enable cross-account access to S3 resources. By explicitly listing the ARN of an external AWS account, an IAM user, or a role from another account in the Principal element of a bucket policy, the resource owner grants permission for those external principals to interact with the bucket. Stating that a bucket policy cannot grant cross-account access directly contradicts a core capability of S3's security model.
- ✓
The IAM user in the other account does not have an IAM policy that allows the S3 action.
Why this is correct
For successful cross-account access to an S3 bucket, a 'two-way street' of permissions is required. While the S3 bucket policy must explicitly grant access to the external account or user, the IAM user in that external account must also possess an identity-based IAM policy that permits the specific S3 actions, such as s3:GetObject or s3:PutObject. If the user's IAM policy is missing or too restrictive, even with a permissive bucket policy, access will be denied, as both policies must allow the action.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.