Courseiva

SCS-C02 Identity and Access Management Practice Question

A company wants to allow an IAM user to list only the objects in a specific S3 bucket named 'my-bucket'. Which IAM policy statement should be used?

⚠ Common exam trap

The trap is mixing up bucket-level and object-level ARNs — candidates often append /* to ListBucket or use GetObject when the requirement is to list objects, confusing 'listing' with 'reading'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::my-bucket"}

The s3:ListBucket action operates on the bucket itself, so the Resource must be the bucket ARN without the /* wildcard: arn:aws:s3:::my-bucket. This grants permission to list objects in that specific bucket only. The /* suffix is used for object-level actions like s3:GetObject, not for ListBucket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    {"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}

    Why it's wrong here

    This policy grants s3:GetObject on the object ARN, which permits downloading a single object's contents but does not authorize the s3:ListBucket action required to enumerate the bucket's keys. Listing is a bucket-level operation, so the Resource must be the bucket ARN (arn:aws:s3:::my-bucket), not the object wildcard. Without s3:ListBucket, any attempt to list objects, such as calling ListObjectsV2 or viewing the bucket in the Amazon S3 console, will fail with AccessDenied.

  • ✓

    {"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::my-bucket"}

    Why this is correct

    This is the correct least-privilege policy because s3:ListBucket is the only permission needed to list the objects in a bucket, and it must be applied to the bucket ARN (arn:aws:s3:::my-bucket). Unlike object-level actions such as GetObject, ListBucket is evaluated against the bucket resource itself, so adding an object-path wildcard would make the ARN invalid. This statement grants exactly the ability to list keys and nothing else, such as reading or writing object contents.

  • ✗

    {"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::my-bucket/*","Condition":{"StringEquals":{"s3:prefix":""}}}

    Why it's wrong here

    This policy incorrectly sets the Resource to the object ARN (my-bucket/*) instead of the bucket ARN, but s3:ListBucket is a bucket-level action that can only be authorized on the bucket itself. Using an object ARN makes the statement ineffective for listing, and the s3:prefix condition is not evaluated because the resource type already mismatches the action. Even if the condition were removed, the wrong resource prevents this statement from granting any actual permission.

  • ✗

    {"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::my-bucket/*"}

    Why it's wrong here

    This policy is far too permissive because s3:* allows every S3 action on all objects, exceeding the requirement to simply list. It also fails to work because s3:ListBucket, which is needed for listing, is a bucket-level action and requires the bucket ARN (arn:aws:s3:::my-bucket) as the Resource; the object ARN used here only covers object-level actions. A correct policy would scope down to a single ListBucket statement on the bucket, avoiding unintended access to object data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.