Courseiva
Security →easyMultiple Choice

DVA-C02 Security Practice Question

A developer needs to share an S3 bucket with a third-party AWS account. The third-party will upload files to the bucket using their own IAM users. The developer creates a bucket policy that grants s3:PutObject to the third-party account's root user. However, the third-party reports that their IAM users cannot upload files. What is the MOST likely reason?

⚠ Common exam trap

DVA-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access, when in fact the third-party's IAM users also need an identity-based policy allowing the action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The third-party's IAM users do not have an IAM policy allowing s3:PutObject.

For cross-account access to S3, both the resource-based policy (bucket policy) and the identity-based policy (IAM policy attached to the third-party's IAM users) must grant the required permission. The bucket policy correctly grants s3:PutObject to the third-party account, but the third-party's IAM users also need an IAM policy allowing s3:PutObject. Without that identity-based permission, the request is denied even though the bucket policy allows it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The third-party's IAM users do not have an IAM policy allowing s3:PutObject.

    Why this is correct

    Even if the S3 bucket policy grants permission to the third-party's account, the specific IAM user or role within that third-party account must also possess an identity-based policy that explicitly allows the s3:PutObject action. Without this corresponding identity-based permission, the request will be denied, as AWS IAM operates on an explicit allow principle where both sides must concur for cross-account access.

  • ✗

    The bucket policy must include a condition requiring encryption.

    Why it's wrong here

    While enforcing encryption for data at rest is a critical security best practice, a bucket policy does not inherently require a condition for encryption (e.g., s3:x-amz-server-side-encryption) for a basic s3:PutObject operation to succeed. The absence of such a condition would simply permit unencrypted uploads, rather than blocking all uploads, making it unnecessary for fundamental access.

  • ✗

    The bucket policy should grant access to the IAM user ARN instead of the root user.

    Why it's wrong here

    A bucket policy can legitimately grant permissions to an external AWS account's root user ARN (e.g., arn:aws:iam::ACCOUNT_ID:root). While granting to specific IAM user ARNs offers finer granularity, granting to the root account allows any IAM user or role within that account to potentially perform the action, provided they also have an identity-based policy. Therefore, granting to the root user ARN is a valid, though less granular, method for cross-account access and not inherently incorrect for the bucket policy itself.

  • ✗

    The developer must create IAM users in their own account for the third-party.

    Why it's wrong here

    Creating IAM users directly within the developer's own AWS account for third-party access is a severe security vulnerability and an unscalable operational practice. This approach necessitates managing external entities' credentials, violates the principle of least privilege by extending trust boundaries unnecessarily, and creates significant administrative overhead. Secure cross-account access should leverage IAM roles and resource policies, allowing third parties to use their own identities.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.