DVA-C02 Security Practice Question
A developer is writing an AWS Lambda function that needs to access an Amazon S3 bucket. The Lambda function's execution role has been granted s3:GetObject permission on the bucket. However, when the function runs, it receives an Access Denied error. The S3 bucket policy allows access only from a specific VPC endpoint. What is the most likely cause of the error?
⚠ Common exam trap
The trap here is assuming that IAM permissions alone are sufficient; bucket policies with VPC endpoint conditions require the request to originate from that endpoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Lambda function is not configured to use the VPC endpoint; it must be associated with the VPC and route traffic through the endpoint.
The S3 bucket policy likely has a condition that restricts access to requests originating from a specific VPC endpoint. For the Lambda function to access the bucket, it must be configured to run within the VPC and use the VPC endpoint for S3. Without this, the request comes from the public internet and is denied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Lambda execution role lacks the s3:ListBucket permission, which is required to access objects in the bucket.
Why it's wrong here
The s3:ListBucket permission is not required to read a specific object with s3:GetObject. The error is Access Denied, but the bucket policy condition on VPC endpoint is the likely cause. Adding ListBucket would not resolve the VPC endpoint restriction.
- ✗
The Lambda function's execution role needs an explicit deny override for the bucket policy condition.
Why it's wrong here
IAM policies cannot override an explicit deny in a bucket policy. The bucket policy condition is not a deny; it's a restriction. The function must meet the condition by using the VPC endpoint. There is no need for a deny override.
- ✗
The S3 bucket policy must be updated to include the Lambda function's IAM role ARN as a principal.
Why it's wrong here
If the bucket policy already allows access from the VPC endpoint, the principal may not need to be explicitly listed. The issue is that the request is not coming through the VPC endpoint. Adding the role ARN would not help if the VPC condition is not met.
- ✓
The Lambda function is not configured to use the VPC endpoint; it must be associated with the VPC and route traffic through the endpoint.
Why this is correct
If the S3 bucket policy restricts access to a specific VPC endpoint, the Lambda function must send requests through that endpoint. This requires the Lambda function to be configured with VPC access, and the VPC must have an S3 gateway endpoint. Without this, the request originates from the public internet and is denied by the bucket policy.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.