Courseiva

SCS-C02 Identity and Access Management Practice Question

A company has an S3 bucket with a bucket policy that grants access to an IAM role used by an application running on EC2. The application is unable to read objects from the bucket, even though the IAM role has the necessary permissions. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The bucket policy denies access to the IAM role.

The most likely cause is that the bucket policy explicitly denies access to the IAM role. Even though the IAM role has the necessary permissions via its attached policies, an explicit deny in the bucket policy overrides any allow, resulting in denied access. Option A is incorrect because cross-account access can be granted with proper permissions. Option C is incorrect because while a missing explicit allow would also deny access by default, the question says the IAM role has the necessary permissions, implying the issue is an explicit deny. Option D is incorrect because if the IAM role had an explicit deny, it would also deny access, but the role is stated to have the necessary permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The bucket is in a different AWS account.

    Why it's wrong here

    A bucket being in a different AWS account is not inherently a cause of denial. S3 bucket policies support cross-account access by specifying the IAM role ARN as the Principal; if the role has the required s3: actions allowed in its identity policy and the bucket policy grants access to that principal (with no explicit deny), the request succeeds. Therefore, an account boundary alone does not block access, and the troubleshooting focus should be on the bucket policy's Allow/Deny statements.

  • ✓

    The bucket policy denies access to the IAM role.

    Why this is correct

    An explicit Deny statement in the bucket policy takes precedence over every Allow, including the IAM role's identity-based permissions. In AWS authorization, the evaluation first defaults to deny, then any allow from identity-based or resource-based policy, but if an explicit deny exists in either policy, the final decision is deny. Thus if the bucket policy contains a statement that denies this role (or the role's account) the s3 operation, access will be blocked even though the role policy appears to grant the necessary permissions.

  • ✗

    The bucket policy does not explicitly allow the IAM role.

    Why it's wrong here

    For a bucket and IAM role in the same AWS account, a bucket policy does not need to separately list the role if the role already has an identity-based allow for the S3 action. S3 combines identity-based and resource-based permissions with a logical OR in the same account, so an absence of an explicit Allow in the bucket policy is not a denial. Unless the bucket policy includes an explicit Deny for the role, the role's own grant is still effective, so 'not explicitly allowing' is not the root cause.

  • ✗

    The IAM role has an explicit deny statement.

    Why it's wrong here

    An explicit deny attached to the IAM role's identity policy would indeed override any allow from the bucket policy and would cause the access failure. However, the scenario states that the role has the necessary permissions, which rules out a role-level explicit deny or any effective deny elsewhere in the identity policy. The cause must therefore lie in the resource-based bucket policy, not in the role's permissions, since explicit deny on the role would be independent of the bucket policy and would contradict the premise.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.