Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer is designing a cross-account access policy. The engineer has an S3 bucket in Account A and wants to grant read access to a user in Account B. Which combination of policies is required?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A bucket policy in Account A allowing the user, and an IAM policy in Account B granting s3:GetObject.

Cross-account access to an S3 bucket requires both a resource-based policy (bucket policy) in Account A that grants permissions to the user in Account B, and an identity-based policy (IAM policy) in Account B that allows the user to perform the s3:GetObject action. Without both, access is denied. Option A is wrong because a bucket policy alone is insufficient; the user still needs an IAM policy in their own account to allow the action. Option B is wrong because bucket ACLs are a legacy mechanism and do not effectively support cross-account access for specific IAM users; they would still require an IAM policy in Account B. Option C is wrong because an IAM policy in Account B alone is insufficient; the bucket policy in Account A must explicitly grant access to the user, as the bucket's default policy denies access from other accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A bucket policy in Account A that allows access to the user in Account B.

    Why it's wrong here

    A bucket policy is a resource-based policy that can grant cross-account access, but for it to take effect, the requesting principal (user in Account B) must also have an identity-based policy in their own account that explicitly allows the same action (s3:GetObject). Without that, the request is denied because the user lacks permission in their own account. Thus, a bucket policy alone is insufficient.

  • ✗

    A bucket ACL in Account A granting access to the user in Account B.

    Why it's wrong here

    A bucket ACL in Account A is a legacy method and does not properly grant cross-account access; it requires an IAM policy in Account B as well, but ACLs are not recommended for this scenario.

  • ✗

    An IAM policy in Account B that grants s3:GetObject to the bucket.

    Why it's wrong here

    An identity-based policy in Account B can grant the user permission to call s3:GetObject, but the request will still fail because the target bucket in Account A has no resource-based policy that allows the external user. Cross-account access requires both an identity-based policy in the requesting account and a resource-based policy on the S3 bucket that explicitly allows the external principal; without the bucket policy, the implicit deny in Account A applies.

  • ✓

    A bucket policy in Account A allowing the user, and an IAM policy in Account B granting s3:GetObject.

    Why this is correct

    This is correct. The bucket policy in Account A acts as a resource-based policy that grants the external user access to the object, while the IAM policy in Account B gives that user the identity-based permission to make the request. Both policies are evaluated, and the union of permissions allows the cross-account S3 GetObject. This follows the standard S3 cross-account access model where both the resource-based and identity-based policies must allow the action.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.