Refer to the exhibit. An IAM user has the following policy attached. The user attempts to download a file named 'config.json' located in the 'secrets' folder of the 'app-logs' S3 bucket. What will be the result of this action?
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"s3:ListBucket",
"s3:GetObject"
],
"Resource": [
"arn:aws:s3:::app-logs",
"arn:aws:s3:::app-logs/*"
]
},
{
"Effect": "Deny",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::app-logs/secrets/*"
}
]
}Trap 1: Access is allowed because the first statement grants GetObject…
The allow statement for the app-logs bucket specifically covers the GetObject action for all objects within that resource. Without a corresponding deny, this would grant access to every file, but the presence of the second statement creates a more restrictive environment for the specified sub-path.
Trap 2: Access is denied because the policy does not include the…
IAM policies prioritize permissions based on the most restrictive rule found across all applicable identity-based and resource-based policies. The lack of PutObject permission is irrelevant to this scenario, as the user is only attempting to download a file, which is governed by the GetObject action.
Trap 3: Access is allowed because the ListBucket action permits viewing all…
The ListBucket action is separate from the GetObject action and only allows the user to see the names of the files within the bucket. It does not grant the ability to read the content of the files, which is governed by the specific object-level permissions defined.
- A
Access is denied because an explicit deny overrides any allow statement.
The explicit deny statement for the secrets prefix takes precedence over the allow statement for the entire bucket. In IAM evaluation logic, any deny will override any allow regardless of the order, ensuring that sensitive files remain protected even when broad read permissions are granted elsewhere.
- B
Access is allowed because the first statement grants GetObject permissions for the whole bucket.
Why it fails: The allow statement for the app-logs bucket specifically covers the GetObject action for all objects within that resource. Without a corresponding deny, this would grant access to every file, but the presence of the second statement creates a more restrictive environment for the specified sub-path.
- C
Access is denied because the policy does not include the s3:PutObject permission.
Why it fails: IAM policies prioritize permissions based on the most restrictive rule found across all applicable identity-based and resource-based policies. The lack of PutObject permission is irrelevant to this scenario, as the user is only attempting to download a file, which is governed by the GetObject action.
- D
Access is allowed because the ListBucket action permits viewing all objects in the bucket.
Why it fails: The ListBucket action is separate from the GetObject action and only allows the user to see the names of the files within the bucket. It does not grant the ability to read the content of the files, which is governed by the specific object-level permissions defined.