DVA-C02 Development with AWS Services Practice Question
Exhibit
Refer to the exhibit.
```
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:GetObject",
"s3:PutObject"
],
"Resource": "arn:aws:s3:::my-bucket/*"
},
{
"Effect": "Deny",
"Action": "s3:DeleteObject",
"Resource": "arn:aws:s3:::my-bucket/*",
"Condition": {
"StringNotEquals": {
"aws:SourceIp": "192.0.2.0/24"
}
}
}
]
}
```An IAM policy attached to an IAM user. What is the effect of this policy on the user's ability to delete objects in the bucket my-bucket?
⚠ Common exam trap
The trap described assumes a specific policy containing a Deny effect with a NotIpAddress condition, but no such policy is shown in the stem. Candidates cannot apply this reasoning without the actual policy text.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user is denied the ability to delete objects regardless of source IP.
The question cannot be answered as written because the IAM policy text is missing. To determine the effect on s3:DeleteObject, the policy's Effect, Action, and Condition (including any IpAddress or NotIpAddress operators) must be provided. Without the policy, no option can be verified as correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user can delete objects from any IP address.
Why it's wrong here
No Allow for DeleteObject.
- ✓
The user is denied the ability to delete objects regardless of source IP.
Why this is correct
No Allow statement exists for DeleteObject, so implicit deny applies.
- ✗
The user can delete objects only if the source IP is not 192.0.2.0/24.
Why it's wrong here
The Deny only applies when not in range; but no Allow means still denied.
- ✗
The user can delete objects only if the source IP is 192.0.2.0/24.
Why it's wrong here
Even if the condition is met, there is no Allow for DeleteObject.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on DVA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Refer to the exhibit. The IAM policy is attached to an IAM role that is assumed by an AWS Lambda function. The Lambda function needs to read and write objects in the 'my-bucket' S3 bucket, but it should never delete objects. What will happen when the function attempts to delete an object?
easy- A.The delete will fail because the Deny statement explicitly denies the delete action.
- B.The delete will succeed because there is no explicit deny for the specific object.
- C.The delete will succeed because the Allow statement gives full access.
- D.The delete will fail because the Allow statement only includes GetObject and PutObject.
Why : In AWS IAM, policy evaluation logic follows the rule that an explicit deny always overrides any allows. Even though the first statement allows all S3 actions (`s3:*`), the second statement explicitly denies `s3:DeleteObject`. Therefore, any attempt to delete an object will be denied.
Variation 2. An IAM policy is attached to an IAM user. The user attempts to upload an object to s3://my-bucket/confidential/report.pdf from an IP address 192.168.1.100. What will happen?
easy- A.The upload succeeds because the Allow statement grants s3:PutObject on all objects in the bucket.
- ✓ B.The upload fails because the Deny statement blocks the request.
- C.The upload succeeds because the IP address 192.168.1.100 matches the condition.
- D.The upload fails because the Deny statement does not have a condition.
Why B: IAM policy evaluation follows an explicit deny priority: any Deny statement overrides any Allow statement when the Deny's condition is met. In this scenario, the Deny statement includes a condition that blocks the request if the source IP is not within a specified range (e.g., 10.0.0.0/8). Since the source IP 192.168.1.100 does not belong to that allowed range, the Deny condition is satisfied, and the Deny takes effect, overriding the Allow statement that grants s3:PutObject on all objects. Therefore, the upload fails.
Variation 3. Refer to the exhibit. An IAM policy is attached to a user. What is the effect when the user tries to upload an object to s3://example-bucket/secret/file.txt?
easy- ✓ A.The upload fails because the Deny statement explicitly denies access to the secret/ prefix.
- B.The upload fails only if the user is not the bucket owner.
- C.The upload succeeds because the Deny statement does not match the specific action.
- D.The upload succeeds because the Allow statement grants s3:PutObject on the bucket.
Why A: The Deny statement in the IAM policy explicitly denies the s3:PutObject action for any object with the prefix secret/ in the example-bucket. Since the user is trying to upload to s3://example-bucket/secret/file.txt, which matches the Deny condition, the request is denied regardless of any Allow statements. AWS IAM policy evaluation is explicit deny by default, meaning a Deny always overrides an Allow.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.