Courseiva

SCS-C02 Identity and Access Management Practice Question

A company has a requirement to grant cross-account access to an S3 bucket named 'shared-data' in Account A (111111111111) to users in Account B (222222222222). The security team has set up a bucket policy in Account A that grants read-only access to the IAM role 'DataReader' in Account B. The bucket policy is as follows: {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Principal":{"AWS":"arn:aws:iam::222222222222:role/DataReader"},"Action":["s3:GetObject"],"Resource":"arn:aws:s3:::shared-data/*"}]}. A user in Account B assumes the 'DataReader' role, but when trying to read an object from the bucket, they receive an 'Access Denied' error. What is the MOST likely reason for this error?

⚠ Common exam trap

SCS-C02 often tests the dual-permission requirement for cross-account access; candidates may assume the bucket policy alone is sufficient, forgetting the need for an identity-based policy in the trusted account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IAM role 'DataReader' does not have an IAM policy that allows s3:GetObject on the bucket.

The most likely reason for the Access Denied error is that the IAM role 'DataReader' in Account B does not have an IAM policy that allows s3:GetObject on the bucket. For cross-account access, both the bucket policy in Account A and the IAM policy in Account B must grant the necessary permissions. The bucket policy alone is not sufficient; the role must also have an identity-based policy allowing the action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The bucket policy principal must be the IAM user ARN, not the role ARN.

    Why it's wrong here

    A role ARN is a valid principal in an S3 bucket policy; unlike some services, S3 accepts IAM role ARNs as principals for cross-account access. So the statement that the principal must be an IAM user ARN is false. The Access Denied is more likely due to missing IAM permissions on the role itself.

  • ✗

    The bucket policy is missing the 's3:ListBucket' action, which is required to read objects.

    Why it's wrong here

    The s3:GetObject action is sufficient to read an object when the caller knows the bucket and object key; s3:ListBucket is only required for operations like listing bucket contents. Thus missing ListBucket would not cause an Access Denied for a direct GetObject call. If the object didn't exist, you'd get NoSuchKey, not Access Denied.

  • ✓

    The IAM role 'DataReader' does not have an IAM policy that allows s3:GetObject on the bucket.

    Why this is correct

    For cross-account S3 access, the IAM role must have an identity-based policy that explicitly allows s3:GetObject on the target bucket. Even if the bucket policy trusts the role, the role's own permissions are evaluated independently; without that allow, the request fails with Access Denied. This is the classic root cause of this scenario.

  • ✗

    The bucket objects are encrypted with a KMS key, and the role does not have permission to decrypt.

    Why it's wrong here

    While KMS encryption would require the role to have kms:Decrypt permission, the question provides no indication of encryption. If encryption were the issue, the error message or configuration would typically reference the KMS key. Without evidence, assuming KMS is speculative, and the simple missing IAM policy is the most likely cause.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.