Courseiva

DVA-C02 Development with AWS Services Practice Question

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:PutObject"
      ],
      "Resource": "arn:aws:s3:::my-bucket/*"
    },
    {
      "Effect": "Deny",
      "Action": "s3:DeleteObject",
      "Resource": "arn:aws:s3:::my-bucket/*",
      "Condition": {
        "StringNotEquals": {
          "aws:SourceIp": "192.0.2.0/24"
        }
      }
    }
  ]
}
```

An IAM policy attached to an IAM user. What is the effect of this policy on the user's ability to delete objects in the bucket my-bucket?

⚠ Common exam trap

The trap described assumes a specific policy containing a Deny effect with a NotIpAddress condition, but no such policy is shown in the stem. Candidates cannot apply this reasoning without the actual policy text.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user is denied the ability to delete objects regardless of source IP.

The question cannot be answered as written because the IAM policy text is missing. To determine the effect on s3:DeleteObject, the policy's Effect, Action, and Condition (including any IpAddress or NotIpAddress operators) must be provided. Without the policy, no option can be verified as correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user can delete objects from any IP address.

    Why it's wrong here

    No Allow for DeleteObject.

  • ✓

    The user is denied the ability to delete objects regardless of source IP.

    Why this is correct

    No Allow statement exists for DeleteObject, so implicit deny applies.

  • ✗

    The user can delete objects only if the source IP is not 192.0.2.0/24.

    Why it's wrong here

    The Deny only applies when not in range; but no Allow means still denied.

  • ✗

    The user can delete objects only if the source IP is 192.0.2.0/24.

    Why it's wrong here

    Even if the condition is met, there is no Allow for DeleteObject.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on DVA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Refer to the exhibit. The IAM policy is attached to an IAM role that is assumed by an AWS Lambda function. The Lambda function needs to read and write objects in the 'my-bucket' S3 bucket, but it should never delete objects. What will happen when the function attempts to delete an object?

easy
  • A.The delete will fail because the Deny statement explicitly denies the delete action.
  • B.The delete will succeed because there is no explicit deny for the specific object.
  • C.The delete will succeed because the Allow statement gives full access.
  • D.The delete will fail because the Allow statement only includes GetObject and PutObject.

Why : In AWS IAM, policy evaluation logic follows the rule that an explicit deny always overrides any allows. Even though the first statement allows all S3 actions (`s3:*`), the second statement explicitly denies `s3:DeleteObject`. Therefore, any attempt to delete an object will be denied.

Variation 2. An IAM policy is attached to an IAM user. The user attempts to upload an object to s3://my-bucket/confidential/report.pdf from an IP address 192.168.1.100. What will happen?

easy
  • A.The upload succeeds because the Allow statement grants s3:PutObject on all objects in the bucket.
  • ✓ B.The upload fails because the Deny statement blocks the request.
  • C.The upload succeeds because the IP address 192.168.1.100 matches the condition.
  • D.The upload fails because the Deny statement does not have a condition.

Why B: IAM policy evaluation follows an explicit deny priority: any Deny statement overrides any Allow statement when the Deny's condition is met. In this scenario, the Deny statement includes a condition that blocks the request if the source IP is not within a specified range (e.g., 10.0.0.0/8). Since the source IP 192.168.1.100 does not belong to that allowed range, the Deny condition is satisfied, and the Deny takes effect, overriding the Allow statement that grants s3:PutObject on all objects. Therefore, the upload fails.

Variation 3. Refer to the exhibit. An IAM policy is attached to a user. What is the effect when the user tries to upload an object to s3://example-bucket/secret/file.txt?

easy
  • ✓ A.The upload fails because the Deny statement explicitly denies access to the secret/ prefix.
  • B.The upload fails only if the user is not the bucket owner.
  • C.The upload succeeds because the Deny statement does not match the specific action.
  • D.The upload succeeds because the Allow statement grants s3:PutObject on the bucket.

Why A: The Deny statement in the IAM policy explicitly denies the s3:PutObject action for any object with the prefix secret/ in the example-bucket. Since the user is trying to upload to s3://example-bucket/secret/file.txt, which matches the Deny condition, the request is denied regardless of any Allow statements. AWS IAM policy evaluation is explicit deny by default, meaning a Deny always overrides an Allow.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.