DVA-C02 Security Practice Question
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-bucket/*",
"Condition": {
"IpAddress": {
"aws:SourceIp": "203.0.113.0/24"
}
}
},
{
"Effect": "Deny",
"Principal": "*",
"Action": "*",
"Resource": "arn:aws:s3:::my-bucket/*"
}
]
}Refer to the exhibit. An S3 bucket policy is set as shown. A developer tries to download an object from my-bucket using the AWS CLI from an IP address in the 203.0.113.0/24 range. What will happen?
⚠ Common exam trap
Many exam-takers assume that an Allow statement will always grant access, forgetting that an explicit Deny for the same action from a matching condition (like a source IP) takes precedence and causes the request to fail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The download fails with an AccessDenied error.
In an S3 bucket policy, explicit Deny statements override any Allow statements. Even though the Allow statement grants s3:GetObject to all principals, the Deny statement explicitly denies s3:GetObject when the request originates from the 203.0.113.0/24 IP range. Since the developer's IP falls within that range, the Deny takes precedence, resulting in an AccessDenied error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy is invalid because of conflicting statements.
Why it's wrong here
AWS IAM policies are designed to accommodate multiple statements, and the presence of both "Allow" and "Deny" effects targeting similar resources or actions does not inherently render the policy invalid. The AWS policy evaluation logic provides a deterministic method for resolving such apparent conflicts, ensuring that the policy remains syntactically and functionally valid. The policy will be evaluated according to the established rules, not rejected as invalid.
- ✗
The download succeeds because the Allow statement matches the request.
Why it's wrong here
While an "Allow" statement might explicitly grant permission for "s3:GetObject" and match the request, the AWS IAM policy evaluation logic dictates that an explicit "Deny" always takes precedence over any "Allow" statement. If there is an explicit "Deny" that applies to the requested action and resource, the request will be denied, regardless of any matching "Allow" statements. Therefore, the presence of a matching "Allow" is insufficient for success when an explicit "Deny" is also present.
- ✗
The download succeeds because the Deny statement does not apply to GetObject.
Why it's wrong here
The "Deny" statement in the exhibit uses the "s3:*" action, which is a wildcard representing all S3 actions. This wildcard explicitly includes "s3:GetObject", the action required for downloading an object. Consequently, the "Deny" statement is indeed applicable to the "GetObject" request, effectively blocking it. The scope of "s3:*" is comprehensive for S3 operations, ensuring the "Deny" covers the download attempt.
- ✓
The download fails with an AccessDenied error.
Why this is correct
The AWS IAM policy evaluation logic follows a strict order of precedence. An explicit "Deny" statement, such as one using "s3:*" on the target resource, always overrides any "Allow" statements, even if an "Allow" statement specifically grants "s3:GetObject" permission. Since the request is explicitly denied by a matching "Deny" statement, the download attempt will result in an "AccessDenied" error, preventing the user from retrieving the object.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.