SAP-C02 Practice Question: Design Solutions for Organizational Complexity
A company is using AWS Organizations with a set of member accounts that need to access a shared Amazon S3 bucket in the master account. The bucket policy allows access only from the member accounts' root user. However, developers in member accounts are unable to access the bucket even when they assume an IAM role. What is the most likely cause?
⚠ Common exam trap
Many candidates assume that granting access to a member account's root user automatically grants access to all IAM users and roles in that account, but in reality, root user ARN is a specific principal that does not cover assumed-role sessions or IAM users unless explicitly included.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The bucket policy grants access to the member account root user ARN, but the role session has a different ARN.
The bucket policy explicitly grants access to the member account's root user ARN (e.g., `arn:aws:iam::123456789012:root`). When a developer assumes an IAM role in the member account, the resulting session has a different ARN (e.g., `arn:aws:sts::123456789012:assumed-role/DevRole/session`). Because the bucket policy's Principal is restricted to the root user ARN, the role session is not recognized as a matching principal, and access is denied. This is a common misconfiguration when mixing root user grants with assumed-role access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The bucket is encrypted with an AWS KMS key that the role does not have permissions to use.
Why it's wrong here
KMS key permissions would affect root users equally, since root also needs kms:Decrypt for SSE-KMS objects; the stem shows root succeeding. It is tempting because KMS grants are a frequent cause of silent AccessDenied on encrypted S3 objects, but the actual discriminator here is the bucket policy's principal element naming account roots rather than role ARNs.
- ✗
The bucket policy requires an explicit Deny for all principals except the root user.
Why it's wrong here
An explicit Deny would block the root user too, contradicting the stated behaviour where root access is permitted. It is tempting because explicit Deny always overrides Allow in IAM evaluation, a genuine and commonly tested rule, but here the policy grants root principals access, so the failure lies in assumed-role principals not matching that principal element.
- ✗
A service control policy (SCP) is denying access to the S3 bucket.
Why it's wrong here
An SCP restricting S3 would also block the member accounts' root users, yet those retain access. SCPs are tempting because they set the maximum permissions boundary for accounts in AWS Organizations, which is a real organisational control, but they cannot selectively permit root while denying assumed roles within the same account.
- ✓
The bucket policy grants access to the member account root user ARN, but the role session has a different ARN.
Why this is correct
Resource-based policies match the exact principal ARN. Granting access to the account root ARN does not cover an assumed role session, whose ARN is arn:aws:sts::account:assumed-role/role/session. The policy must name the role or account principal explicitly.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.