SCS-C02 Identity and Access Management Practice Question
A security engineer is troubleshooting an issue where an IAM policy allows access to S3 but the user is denied access to a specific bucket. The policy has the following statement:
{
"Effect": "Allow",
"Action": "s3:*",
"Resource": "*"
}What is the most likely cause of the denial?
⚠ Common exam trap
SCS-C02 often tests the misconception that a broad Allow policy 'wins' or that AWS auto-narrows permissions — candidates forget that explicit Deny always overrides Allow in the IAM evaluation chain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An explicit deny statement in a different policy (e.g., SCP, permissions boundary) is overriding the allow.
AWS evaluates all applicable policies using a union-of-allows model, but any explicit Deny anywhere in the evaluation chain (identity policy, resource policy, SCP, permissions boundary, session policy) wins over every Allow. A broad Allow like s3:* on * does not get 'narrowed' by AWS — it is simply overridden when an explicit Deny matches the same action/resource. The most likely cause is therefore an explicit Deny in an SCP, permissions boundary, or similar policy that targets the specific bucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy statement is too broad and AWS automatically denies access to specific buckets.
Why it's wrong here
AWS IAM does not evaluate the breadth of a policy statement and automatically deny access to specific buckets. A broad allow statement simply grants permissions to all actions and resources listed; it never implies an automatic restriction. Access is denied only when there is an explicit deny, when no applicable allow exists, or when the request fails condition or resource boundaries. Therefore, this cannot be the cause of the persistent denied error.
- ✓
An explicit deny statement in a different policy (e.g., SCP, permissions boundary) is overriding the allow.
Why this is correct
An explicit deny in any applicable policy, such as a service control policy (SCP) attached to an organizational unit or a permissions boundary on the IAM principal, overrides any allow in the user's own IAM policy. During policy evaluation, AWS determines the final decision by first considering all applicable policies and applying the rule that an explicit deny takes precedence over any allow. Even if the user's policy grants s3:GetObject, the explicit deny in the SCP or boundary will cause the request to fail with an access denied error. To resolve this, the security engineer must identify and modify the deny statement or remove the restricting boundary.
- ✗
The S3 bucket has a bucket policy that denies access to the user.
Why it's wrong here
This is incorrect. A bucket policy with a deny could cause the denial, but it is not the most likely cause given the IAM allow and the troubleshooting context of IAM policies. The question asks for the most likely cause, which is an explicit deny in a different policy.
- ✗
The policy is attached to the user but the user is assuming a role that does not have S3 permissions.
Why it's wrong here
This is incorrect. Assuming a role would change the effective permissions, but there is no indication the user is assuming a role. The user's own policy is an allow, and role assumption is not mentioned.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.