SCS-C02 Identity and Access Management Practice Question
A company wants to allow a Lambda function to read objects from an S3 bucket in the same account. What should be done?
⚠ Common exam trap
Many exam-takers confuse the Lambda service principal (lambda.amazonaws.com) with the Lambda execution role, incorrectly assuming that a bucket policy can grant access directly to the Lambda service rather than to the IAM role that the Lambda function assumes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an IAM role with an S3 read policy and attach it to the Lambda function.
Lambda functions require an IAM role (execution role) to obtain temporary AWS credentials via the AWS Security Token Service (STS). Attaching a policy with s3:GetObject permissions to this role grants the Lambda function the necessary access to read objects from the S3 bucket without hardcoding long-term credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store IAM user access keys in the Lambda function's environment variables.
Why it's wrong here
Storing IAM user access keys in Lambda environment variables introduces long-lived static credentials that are not rotated automatically and can be exposed through function configuration logs, version history, or misconfigured KMS encryption. Lambda does not need long-term keys because it can use an execution role to obtain short-lived STS credentials at runtime. This violates the IAM best practice of using roles for workloads and creates unnecessary risk if the keys are ever leaked.
- ✓
Create an IAM role with an S3 read policy and attach it to the Lambda function.
Why this is correct
Create an IAM role with a policy allowing s3:GetObject on the specific bucket and object ARNs, then set that role as the Lambda function's execution role. The role's trust policy must allow lambda.amazonaws.com to assume it, after which Lambda calls STS to receive temporary credentials scoped to that role. These credentials are automatically rotated and passed to the AWS SDK, making this the least-privilege, auditable way to grant the function read access to S3.
- ✗
Add a bucket policy allowing s3:GetObject for the Lambda service principal.
Why it's wrong here
A bucket policy that grants s3:GetObject to the Lambda service principal (Service: lambda.amazonaws.com) is ineffective because the Lambda service itself never calls S3; the function's code makes those calls using the execution role's assumed-role session. From S3's perspective, the principal is arn:aws:sts::account:assumed-role/role-name/task-name, not the Lambda service principal. Therefore, the policy would not match the actual caller and does not grant the specific function the required access.
- ✗
Configure the S3 bucket to be public.
Why it's wrong here
Making the S3 bucket public disables authentication and authorization, allowing anyone who knows the object URL to perform s3:GetObject and exposing all objects in the bucket rather than only the ones Lambda needs. This is the opposite of least privilege, would fail security and compliance reviews, and does not give Lambda its own auditable IAM identity. It also leaves the data at risk even if the function's access pattern is later restricted.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.