DVA-C02 Security Practice Question
Which of the following are valid ways to secure access to an Amazon S3 bucket? (Choose TWO.)
⚠ Common exam trap
Candidates often confuse network-level security controls (like NACLs and Security Groups) with resource-level access controls, mistakenly thinking they can be applied to S3 buckets, which are global services not bound to a VPC subnet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Bucket policies
Bucket policies are a form of resource-based policy that you attach directly to an S3 bucket. They allow you to grant or deny access to the bucket and its objects for principals (users, roles, or AWS accounts) using the AWS JSON policy language. This is a primary and native way to control access to S3 resources, making option A correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Bucket policies
Why this is correct
Bucket policies are resource-based access policies directly attached to an S3 bucket, defining who (principals like IAM users, roles, or other AWS accounts) can perform which actions (e.g., GetObject, PutObject) on the objects within that specific bucket. They are fundamental for granting cross-account access, defining public access configurations, or restricting access based on IP addresses. These policies act as a primary access control layer, evaluated directly by the S3 service upon every request to the bucket.
- ✗
CloudFront distribution
Why it's wrong here
CloudFront is a global content delivery network (CDN) service designed to cache and deliver content with low latency, not primarily an access control mechanism for S3 buckets. While CloudFront can be configured with Origin Access Control (OAC) or Origin Access Identity (OAI) to restrict direct S3 bucket access, this setup ensures content is served *only* through CloudFront. However, CloudFront itself does not define the access permissions for the S3 bucket; the underlying S3 bucket still relies on its own policies for direct access control.
- ✓
IAM policies
Why this is correct
IAM policies are identity-based access policies attached to IAM principals such as users, groups, or roles, defining their permissions across AWS services. For S3, an IAM policy specifies what actions a particular principal is allowed or denied to perform on S3 resources (buckets or objects). These policies are fundamental for managing granular permissions for individual identities within an AWS account, complementing bucket policies by controlling who can initiate requests to S3 resources.
- ✗
Network ACLs
Why it's wrong here
Network ACLs (NACLs) operate as stateless firewalls at the subnet level within an Amazon Virtual Private Cloud (VPC), controlling inbound and outbound traffic for resources *inside* that subnet. S3 is a global, highly available object storage service that exists outside of a customer's specific VPC infrastructure. Consequently, NACLs cannot be used to directly secure access to S3 buckets, as S3 endpoints are accessed over the public internet or via VPC endpoints, not through subnet-level network filtering.
- ✗
Security groups
Why it's wrong here
Security groups function as stateful virtual firewalls for EC2 instances and other network interface-attached resources, controlling traffic at the instance level within a VPC. They define rules for allowed inbound and outbound network connections to specific instances. Since S3 buckets are public cloud storage endpoints and not resources deployed within a customer's VPC or attached to an EC2 instance's network interface, security groups have no direct applicability in securing access to S3.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.