Courseiva
Security →easyMultiple Choice

DVA-C02 Security Practice Question

A developer needs to grant an IAM user read-only access to an S3 bucket named 'my-bucket'. Which IAM policy statement should be attached?

⚠ Common exam trap

The trap here is that candidates often forget to include both the bucket ARN and the object ARN, or they mistakenly use a single ARN like `arn:aws:s3:::my-bucket/*` for both actions, which would fail for `s3:ListBucket` because it requires the bucket-level ARN.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

{"Effect":"Allow","Action":["s3:GetObject","s3:ListBucket"],"Resource":["arn:aws:s3:::my-bucket","arn:aws:s3:::my-bucket/*"]}

It grants read-only access by allowing the `s3:GetObject` action (to read objects) and the `s3:ListBucket` action (to list objects in the bucket). The resources are correctly specified: `arn:aws:s3:::my-bucket` for the bucket-level `ListBucket` action and `arn:aws:s3:::my-bucket/*` for the object-level `GetObject` action. This combination provides the minimal permissions needed for read-only access without allowing write or delete operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    {"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::my-bucket/*"}

    Why it's wrong here

    Using the s3:* wildcard action grants every possible S3 permission including PutObject, DeleteObject, and PutBucketPolicy, which is far broader than the read-only requirement and violates least privilege by letting the user modify or delete objects and even alter the bucket's own configuration, not just read its contents.

  • ✓

    {"Effect":"Allow","Action":["s3:GetObject","s3:ListBucket"],"Resource":["arn:aws:s3:::my-bucket","arn:aws:s3:::my-bucket/*"]}

    Why this is correct

    Pairing s3:ListBucket with the bucket-level ARN and s3:GetObject with the object-level wildcard ARN correctly grants exactly the two actions needed for read-only access: enumerating the bucket's contents and downloading individual objects, while granting no write or delete permissions on either the bucket or its objects.

  • ✗

    {"Effect":"Deny","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}

    Why it's wrong here

    An explicit Deny on s3:GetObject blocks the ability to read objects entirely rather than granting it, which is the opposite of the stated requirement to give the user read-only access; this statement would prevent even legitimate read operations instead of enabling them.

  • ✗

    {"Effect":"Allow","Action":["s3:PutObject","s3:DeleteObject"],"Resource":"arn:aws:s3:::my-bucket/*"}

    Why it's wrong here

    s3:PutObject and s3:DeleteObject are write and delete actions respectively that let the user upload new objects or overwrite and remove existing ones; granting these directly contradicts a read-only access requirement and omits the s3:GetObject and s3:ListBucket actions actually needed to read data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.