Courseiva
Security and Compliance →easyMultiple Choice

Cross-Account S3 Access: Bucket Policy + IAM Policy

A DevOps engineer needs to grant cross-account access to an S3 bucket in Account A for a user in Account B. Which combination of policies is required?

⚠ Common exam trap

Many candidates assume a bucket policy alone is sufficient for cross-account access, forgetting that the external user must also have an IAM policy that explicitly allows the S3 actions, leading them to incorrectly select Option D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An S3 bucket policy in Account A and an IAM policy in Account B.

Cross-account access to an S3 bucket requires both a resource-based policy (the S3 bucket policy in Account A) that grants the necessary permissions to the principal from Account B, and an identity-based policy (an IAM policy in Account B) attached to the user that allows the S3 actions. The bucket policy explicitly authorizes the external user (by ARN), while the IAM policy ensures the user has the required permissions to initiate the request. Without both, the request will fail due to the lack of either resource-side authorization or identity-side authorization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    An S3 bucket policy in Account A and an IAM policy in Account B.

    Why this is correct

    For cross-account S3 access, both an S3 bucket policy in the owning account (Account A) that explicitly allows the external principal (e.g., an IAM user or role in Account B) to perform the desired actions, and an IAM policy in Account B that grants that same principal permission to call S3 on the bucket ARN are required. AWS evaluates identity-based policies and resource-based policies together, so a request succeeds only if both sides explicitly allow it. Without either, the request is implicitly denied.

  • ✗

    An IAM role in Account A and an IAM policy in Account B.

    Why it's wrong here

    Using an IAM role in Account A would require the user in Account B to assume the role via STS, which is unnecessary and overly broad because the role's permissions apply to all resources in Account A it can access, not just the specific S3 bucket. It also requires a trust policy on the role and complicates the access pattern. The IAM policy in Account B alone cannot grant access to a resource in another account unless the resource owner allows it, so this combination does not correctly achieve least-privilege access to the bucket.

  • ✗

    Only an IAM policy in Account B.

    Why it's wrong here

    An IAM policy in Account B alone is insufficient because permissions are the intersection of identity-based policies and resource-based policies in the resource owner's account. Even if the IAM user in Account B has a policy allowing s3:GetObject on the bucket ARN, the bucket in Account A has no bucket policy allowing that user as a principal, so the request is implicitly denied by default. Cross-account access requires explicit authorization from the resource account.

  • ✗

    Only an S3 bucket policy in Account A.

    Why it's wrong here

    An S3 bucket policy in Account A alone is insufficient because the IAM user in Account B must also be explicitly allowed by an identity-based policy in their own account to perform the requested S3 action. While the bucket policy grants cross-account permission to an external principal, AWS denies a request if the principal's own IAM policy does not also grant the action. The two policies work in conjunction; the absence of either results in an 'AccessDenied' error.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization wants to grant cross-account access to an S3 bucket in Account A to a user in Account B. Which policy configuration is required?

easy
  • ✓ A.A bucket policy in Account A and an IAM user policy in Account B
  • B.An S3 bucket ACL granting access to the user in Account B
  • C.An IAM user policy in Account B allowing access to the bucket
  • D.A bucket policy in Account A granting access to the user in Account B

Why A: Cross-account access to an S3 bucket requires both a resource-based policy (bucket policy) on the bucket in Account A granting access to the user in Account B, and an identity-based policy (IAM user policy) in Account B allowing the user to access the bucket. Option A correctly includes both policies. Option B is incorrect because S3 bucket ACLs are legacy and not recommended for cross-account access. Option C is missing the bucket policy in Account A, so it is insufficient. Option D is missing the IAM user policy in Account B, so it is insufficient.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.