Courseiva
Security →easyMultiple Select

DVA-C02 Security Practice Question

Which of the following are valid ways to secure access to an Amazon S3 bucket? (Choose TWO.)

⚠ Common exam trap

Candidates often confuse network-level security controls (like NACLs and Security Groups) with resource-level access controls, mistakenly thinking they can be applied to S3 buckets, which are global services not bound to a VPC subnet.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Bucket policies

Bucket policies are a form of resource-based policy that you attach directly to an S3 bucket. They allow you to grant or deny access to the bucket and its objects for principals (users, roles, or AWS accounts) using the AWS JSON policy language. This is a primary and native way to control access to S3 resources, making option A correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Bucket policies

    Why this is correct

    Bucket policies are resource-based access policies directly attached to an S3 bucket, defining who (principals like IAM users, roles, or other AWS accounts) can perform which actions (e.g., GetObject, PutObject) on the objects within that specific bucket. They are fundamental for granting cross-account access, defining public access configurations, or restricting access based on IP addresses. These policies act as a primary access control layer, evaluated directly by the S3 service upon every request to the bucket.

  • ✗

    CloudFront distribution

    Why it's wrong here

    CloudFront is a global content delivery network (CDN) service designed to cache and deliver content with low latency, not primarily an access control mechanism for S3 buckets. While CloudFront can be configured with Origin Access Control (OAC) or Origin Access Identity (OAI) to restrict direct S3 bucket access, this setup ensures content is served *only* through CloudFront. However, CloudFront itself does not define the access permissions for the S3 bucket; the underlying S3 bucket still relies on its own policies for direct access control.

  • ✓

    IAM policies

    Why this is correct

    IAM policies are identity-based access policies attached to IAM principals such as users, groups, or roles, defining their permissions across AWS services. For S3, an IAM policy specifies what actions a particular principal is allowed or denied to perform on S3 resources (buckets or objects). These policies are fundamental for managing granular permissions for individual identities within an AWS account, complementing bucket policies by controlling who can initiate requests to S3 resources.

  • ✗

    Network ACLs

    Why it's wrong here

    Network ACLs (NACLs) operate as stateless firewalls at the subnet level within an Amazon Virtual Private Cloud (VPC), controlling inbound and outbound traffic for resources *inside* that subnet. S3 is a global, highly available object storage service that exists outside of a customer's specific VPC infrastructure. Consequently, NACLs cannot be used to directly secure access to S3 buckets, as S3 endpoints are accessed over the public internet or via VPC endpoints, not through subnet-level network filtering.

  • ✗

    Security groups

    Why it's wrong here

    Security groups function as stateful virtual firewalls for EC2 instances and other network interface-attached resources, controlling traffic at the instance level within a VPC. They define rules for allowed inbound and outbound network connections to specific instances. Since S3 buckets are public cloud storage endpoints and not resources deployed within a customer's VPC or attached to an EC2 instance's network interface, security groups have no direct applicability in securing access to S3.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.