Courseiva

DVA-C02 Development with AWS Services Practice Question

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:PutObject"
      ],
      "Resource": "arn:aws:s3:::my-bucket/*"
    },
    {
      "Effect": "Deny",
      "Action": "s3:*",
      "Resource": "arn:aws:s3:::my-bucket/confidential/*"
    }
  ]
}

Refer to the exhibit. An IAM policy is attached to an IAM user. The user tries to upload a file to s3://my-bucket/confidential/report.pdf. What will happen?

⚠ Common exam trap

Candidates often assume an Allow statement alone determines access, forgetting that an explicit Deny in the same policy overrides any Allow, regardless of the order in which the statements appear.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The upload fails because the Deny statement overrides the Allow.

IAM policy evaluation logic dictates that an explicit Deny always overrides any Allow. In this scenario, the Deny statement denies `s3:PutObject` on the path `arn:aws:s3:::my-bucket/confidential/*`, which matches the user's upload target `s3://my-bucket/confidential/report.pdf`. Even though the Allow statement grants `s3:PutObject` on `arn:aws:s3:::my-bucket/*`, the explicit Deny takes precedence, causing the upload to fail.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The upload fails because the Deny statement overrides the Allow.

    Why this is correct

    AWS IAM policy evaluation logic dictates that an explicit Deny statement always takes precedence over any Allow statement, even if the Allow statement would otherwise grant the requested permission. In this scenario, despite an Allow for s3:PutObject, the presence of a Deny for the same action on the bucket ensures the upload operation is blocked. This fundamental rule prioritizes security by preventing unintended access, making the upload fail.

  • ✗

    The upload succeeds because the Deny statement applies only to the bucket, not the user.

    Why it's wrong here

    The Deny statement in an IAM identity-based policy directly restricts the user to whom the policy is attached. It does not solely apply to the resource in isolation; rather, it defines what actions the user is prohibited from performing on specified resources. Therefore, the Deny statement effectively prevents the user from uploading objects to the bucket, making the upload fail, not succeed.

  • ✗

    The upload fails because the policy does not allow PutObject on that path.

    Why it's wrong here

    The policy's Allow statement actually grants s3:PutObject on `arn:aws:s3:::my-example-bucket/*`, which covers any path within the bucket. The upload failure is not due to a lack of an initial permission grant for the specific path. Instead, the explicit Deny statement for s3:PutObject on the entire bucket overrides this general Allow, causing the operation to be rejected.

  • ✗

    The upload succeeds because the Allow statement grants PutObject.

    Why it's wrong here

    While the policy does contain an Allow statement for s3:PutObject on the bucket, the presence of an explicit Deny statement for the same action and resource fundamentally alters the outcome. According to AWS IAM policy evaluation, an explicit Deny always overrides any existing Allow. Consequently, the Allow statement's grant is nullified by the Deny, preventing the upload from succeeding.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DVA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Refer to the exhibit. An IAM policy is attached to an IAM user. The user tries to upload an object to s3://my-bucket/confidential/report.pdf. What is the outcome?

hard
  • A.The upload succeeds because the Allow statement grants s3:PutObject on the bucket.
  • B.The upload fails because there is no Allow statement for the confidential prefix.
  • ✓ C.The upload fails because the Deny statement explicitly denies access to the confidential prefix.
  • D.The upload fails because the policy is malformed.

Why C: The IAM policy includes an explicit Deny statement for s3:PutObject on the `confidential` prefix, which overrides any Allow statements. AWS IAM evaluates policies with explicit Denies taking precedence over Allows, so the upload to `s3://my-bucket/confidential/report.pdf` is blocked regardless of the Allow statement on the bucket.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.