SCS-C02 Identity and Access Management Practice Question
A company wants to allow an IAM user to list only the objects in a specific S3 bucket named 'my-bucket'. Which IAM policy statement should be used?
⚠ Common exam trap
The trap is mixing up bucket-level and object-level ARNs — candidates often append /* to ListBucket or use GetObject when the requirement is to list objects, confusing 'listing' with 'reading'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::my-bucket"}
The s3:ListBucket action operates on the bucket itself, so the Resource must be the bucket ARN without the /* wildcard: arn:aws:s3:::my-bucket. This grants permission to list objects in that specific bucket only. The /* suffix is used for object-level actions like s3:GetObject, not for ListBucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
{"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}
Why it's wrong here
This policy grants s3:GetObject on the object ARN, which permits downloading a single object's contents but does not authorize the s3:ListBucket action required to enumerate the bucket's keys. Listing is a bucket-level operation, so the Resource must be the bucket ARN (arn:aws:s3:::my-bucket), not the object wildcard. Without s3:ListBucket, any attempt to list objects, such as calling ListObjectsV2 or viewing the bucket in the Amazon S3 console, will fail with AccessDenied.
- ✓
{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::my-bucket"}
Why this is correct
This is the correct least-privilege policy because s3:ListBucket is the only permission needed to list the objects in a bucket, and it must be applied to the bucket ARN (arn:aws:s3:::my-bucket). Unlike object-level actions such as GetObject, ListBucket is evaluated against the bucket resource itself, so adding an object-path wildcard would make the ARN invalid. This statement grants exactly the ability to list keys and nothing else, such as reading or writing object contents.
- ✗
{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::my-bucket/*","Condition":{"StringEquals":{"s3:prefix":""}}}
Why it's wrong here
This policy incorrectly sets the Resource to the object ARN (my-bucket/*) instead of the bucket ARN, but s3:ListBucket is a bucket-level action that can only be authorized on the bucket itself. Using an object ARN makes the statement ineffective for listing, and the s3:prefix condition is not evaluated because the resource type already mismatches the action. Even if the condition were removed, the wrong resource prevents this statement from granting any actual permission.
- ✗
{"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::my-bucket/*"}
Why it's wrong here
This policy is far too permissive because s3:* allows every S3 action on all objects, exceeding the requirement to simply list. It also fails to work because s3:ListBucket, which is needed for listing, is a bucket-level action and requires the bucket ARN (arn:aws:s3:::my-bucket) as the Resource; the object ARN used here only covers object-level actions. A correct policy would scope down to a single ListBucket statement on the bucket, avoiding unintended access to object data.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.