DVA-C02 Security Practice Question
A developer needs to share an S3 bucket with a third-party AWS account. The third-party will upload files to the bucket using their own IAM users. The developer creates a bucket policy that grants s3:PutObject to the third-party account's root user. However, the third-party reports that their IAM users cannot upload files. What is the MOST likely reason?
⚠ Common exam trap
DVA-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access, when in fact the third-party's IAM users also need an identity-based policy allowing the action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The third-party's IAM users do not have an IAM policy allowing s3:PutObject.
For cross-account access to S3, both the resource-based policy (bucket policy) and the identity-based policy (IAM policy attached to the third-party's IAM users) must grant the required permission. The bucket policy correctly grants s3:PutObject to the third-party account, but the third-party's IAM users also need an IAM policy allowing s3:PutObject. Without that identity-based permission, the request is denied even though the bucket policy allows it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The third-party's IAM users do not have an IAM policy allowing s3:PutObject.
Why this is correct
Even if the S3 bucket policy grants permission to the third-party's account, the specific IAM user or role within that third-party account must also possess an identity-based policy that explicitly allows the s3:PutObject action. Without this corresponding identity-based permission, the request will be denied, as AWS IAM operates on an explicit allow principle where both sides must concur for cross-account access.
- ✗
The bucket policy must include a condition requiring encryption.
Why it's wrong here
While enforcing encryption for data at rest is a critical security best practice, a bucket policy does not inherently require a condition for encryption (e.g., s3:x-amz-server-side-encryption) for a basic s3:PutObject operation to succeed. The absence of such a condition would simply permit unencrypted uploads, rather than blocking all uploads, making it unnecessary for fundamental access.
- ✗
The bucket policy should grant access to the IAM user ARN instead of the root user.
Why it's wrong here
A bucket policy can legitimately grant permissions to an external AWS account's root user ARN (e.g., arn:aws:iam::ACCOUNT_ID:root). While granting to specific IAM user ARNs offers finer granularity, granting to the root account allows any IAM user or role within that account to potentially perform the action, provided they also have an identity-based policy. Therefore, granting to the root user ARN is a valid, though less granular, method for cross-account access and not inherently incorrect for the bucket policy itself.
- ✗
The developer must create IAM users in their own account for the third-party.
Why it's wrong here
Creating IAM users directly within the developer's own AWS account for third-party access is a severe security vulnerability and an unscalable operational practice. This approach necessitates managing external entities' credentials, violates the principle of least privilege by extending trust boundaries unnecessarily, and creates significant administrative overhead. Secure cross-account access should leverage IAM roles and resource policies, allowing third parties to use their own identities.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.