Courseiva

SAP-C02 Least-privilege permissions Practice Question

A company is deploying a new application on AWS and wants to implement a least-privilege IAM policy for an EC2 instance that needs to read from an S3 bucket (my-bucket) and write logs to CloudWatch Logs. Which TWO statements should be included in the IAM policy? (Choose two.)

⚠ Common exam trap

The trap is that candidates often include unnecessary permissions (like s3:PutObject) beyond what the stem explicitly requires, failing the least-privilege requirement. Always scope permissions to only the actions and resources stated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

{"Effect": "Allow", "Action": ["s3:GetObject"], "Resource": "arn:aws:s3:::my-bucket/*"}

Option A is correct because it grants only the s3:GetObject action needed to read objects from my-bucket, scoped to the bucket's object ARN arn:aws:s3:::my-bucket/*, which satisfies least privilege for read access. Option C is correct because it grants exactly the CloudWatch Logs actions required to write logs (logs:CreateLogStream and logs:PutLogEvents) and scopes them to the specific log group ARN, avoiding broader permissions. Option B is incorrect because s3:* grants all S3 actions on the bucket, violating least privilege. Option D is incorrect because logs:PutLogEvents on Resource "*" is overly broad and also omits logs:CreateLogStream needed to create the stream. Option E is incorrect because s3:PutObject grants write access to S3, which the instance does not need since it only reads from the bucket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    {"Effect": "Allow", "Action": ["s3:GetObject"], "Resource": "arn:aws:s3:::my-bucket/*"}

    Why this is correct

    Granting s3:GetObject on arn:aws:s3:::my-bucket/* authorises reads of objects within the bucket, matching the least-privilege read requirement. The wildcard covers every object key while excluding bucket-level actions such as s3:ListBucket, so only the access the EC2 instance genuinely needs is permitted.

  • ✗

    {"Effect": "Allow", "Action": ["s3:*"], "Resource": "arn:aws:s3:::my-bucket/*"}

    Why it's wrong here

    Granting `s3:*` on `my-bucket/*` violates least privilege by permitting deletes, writes and ACL changes, not just reads. It is tempting because wildcard actions simplify policy authoring when an instance genuinely needs full bucket administration, such as a backup agent managing objects and lifecycle. Here, only `s3:GetObject` on that ARN is required.

  • ✓

    {"Effect": "Allow", "Action": ["logs:CreateLogStream", "logs:PutLogEvents"], "Resource": "arn:aws:logs:us-east-1:123456789012:log-group:my-log-group:*"}

    Why this is correct

    This statement grants only the two CloudWatch Logs write actions the instance needs, scoped to the specific log group's ARN. It satisfies least privilege by avoiding wildcard resources or unrelated actions, permitting log stream creation and event publishing without broader access.

  • ✗

    {"Effect": "Allow", "Action": ["logs:PutLogEvents"], "Resource": "*"}

    Why it's wrong here

    Using a wildcard resource grants log-write permission across every log group in the account, breaching least privilege, which requires the ARN of the specific target log group. It is tempting because logs:PutLogEvents is the correct action for writing log events, and a wildcard works when the destination log group is genuinely unknown or spans all groups.

  • ✗

    {"Effect": "Allow", "Action": ["s3:PutObject"], "Resource": "arn:aws:s3:::my-bucket/*"}

    Why it's wrong here

    Granting s3:PutObject permits uploads, not the read access the instance requires; the stem specifies reading from my-bucket, which needs s3:GetObject on the object ARN. PutObject is the correct action when an instance must write or upload objects into a bucket, such as storing generated reports or application output.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.