SCS-C02 Identity and Access Management Practice Question
A company has a requirement to grant cross-account access to an S3 bucket named 'shared-data' in Account A (111111111111) to users in Account B (222222222222). The security team has set up a bucket policy in Account A that grants read-only access to the IAM role 'DataReader' in Account B. The bucket policy is as follows: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":{"AWS":"arn:aws:iam::222222222222:role/DataReader"},"Action":["s3:GetObject"],"Resource":"arn:aws:s3:::shared-data/*"}]}. A user in Account B assumes the 'DataReader' role, but when trying to read an object from the bucket, they receive an 'Access Denied' error. What is the MOST likely reason for this error?
⚠ Common exam trap
SCS-C02 often tests the dual-permission requirement for cross-account access; candidates may assume the bucket policy alone is sufficient, forgetting the need for an identity-based policy in the trusted account.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM role 'DataReader' does not have an IAM policy that allows s3:GetObject on the bucket.
The most likely reason for the Access Denied error is that the IAM role 'DataReader' in Account B does not have an IAM policy that allows s3:GetObject on the bucket. For cross-account access, both the bucket policy in Account A and the IAM policy in Account B must grant the necessary permissions. The bucket policy alone is not sufficient; the role must also have an identity-based policy allowing the action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The bucket policy principal must be the IAM user ARN, not the role ARN.
Why it's wrong here
A role ARN is a valid principal in an S3 bucket policy; unlike some services, S3 accepts IAM role ARNs as principals for cross-account access. So the statement that the principal must be an IAM user ARN is false. The Access Denied is more likely due to missing IAM permissions on the role itself.
- ✗
The bucket policy is missing the 's3:ListBucket' action, which is required to read objects.
Why it's wrong here
The s3:GetObject action is sufficient to read an object when the caller knows the bucket and object key; s3:ListBucket is only required for operations like listing bucket contents. Thus missing ListBucket would not cause an Access Denied for a direct GetObject call. If the object didn't exist, you'd get NoSuchKey, not Access Denied.
- ✓
The IAM role 'DataReader' does not have an IAM policy that allows s3:GetObject on the bucket.
Why this is correct
For cross-account S3 access, the IAM role must have an identity-based policy that explicitly allows s3:GetObject on the target bucket. Even if the bucket policy trusts the role, the role's own permissions are evaluated independently; without that allow, the request fails with Access Denied. This is the classic root cause of this scenario.
- ✗
The bucket objects are encrypted with a KMS key, and the role does not have permission to decrypt.
Why it's wrong here
While KMS encryption would require the role to have kms:Decrypt permission, the question provides no indication of encryption. If encryption were the issue, the error message or configuration would typically reference the KMS key. Without evidence, assuming KMS is speculative, and the simple missing IAM policy is the most likely cause.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.