Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer needs to grant cross-account read access to an S3 bucket in Account A to a user in Account B. What is the correct combination of actions?

⚠ Common exam trap

Many candidates assume either a bucket policy alone or an IAM policy alone is sufficient for cross-account access, failing to recognize that AWS requires both the resource-based policy to grant access to the external principal and the identity-based policy to authorize the user to make the request.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a bucket policy in Account A granting access to the principal in Account B, and attach an IAM policy to the user in Account B allowing the action

Cross-account S3 access requires both a bucket policy in the resource account (Account A) that explicitly grants the cross-account principal (the user in Account B) the s3:GetObject action, and an IAM policy attached to the user in Account B that allows the same action. This two-way authorization is necessary because the bucket policy controls access to the S3 resource, while the IAM policy controls the user's permissions to initiate the request. Without both, the request will be denied by either the resource-based policy or the identity-based policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Attach an IAM policy to the user in Account B allowing the action; no bucket policy needed

    Why it's wrong here

    This approach is insufficient because S3 cross-account access requires an explicit resource-based policy on the bucket in Account A. An IAM policy attached to the user in Account B only defines the user's permissions within its own account, but it cannot authorize access to a resource owned by another account. By default, the bucket in Account A is private to Account A, so without a bucket policy that grants the Account B user (or its account) permission, the request is denied at the S3 service level. Thus, a user policy alone cannot enable cross-account reads.

  • ✗

    Apply a bucket policy in Account A granting access to the user in Account B; no user policy needed

    Why it's wrong here

    This option is incomplete because it omits the mandatory identity-based permission in Account B. While the bucket policy in Account A may explicitly grant access to the Account B user, IAM requires that for cross-account access, the principal's own account must also authorize the action. Even if the bucket policy allows s3:GetObject, the Account B user has no IAM policy allowing that action, so the request will be denied during IAM policy evaluation. The user in Account B must attach an IAM policy that permits the read action to complete the authorization chain.

  • ✗

    Use S3 bucket ACLs to grant READ access to the Account B user

    Why it's wrong here

    S3 bucket ACLs are a legacy authorization mechanism and are not the recommended way to grant cross-account access. ACLs do not support IAM roles, conditions, or many fine-grained permissions, and they still require the Account B user to have an IAM policy that allows the s3:GetObject action. Additionally, many S3 features (like bucket policies) are preferred over ACLs, and AWS discourages using ACLs except when you need to grant basic read/write permissions to specific AWS accounts. Therefore, relying solely on an ACL is both technically insufficient and an outdated approach for cross-account read access.

  • ✓

    Apply a bucket policy in Account A granting access to the principal in Account B, and attach an IAM policy to the user in Account B allowing the action

    Why this is correct

    This is the correct and complete solution. For cross-account S3 access, AWS requires that both the resource-based policy (bucket policy) in Account A and the identity-based policy (IAM policy) attached to the user in Account B explicitly allow the s3:GetObject action. The bucket policy grants the Account B principal access to the bucket, while the IAM policy provisions that principal with the necessary action permissions in its own account. Without either side, the request is denied. This dual-policy requirement ensures both the resource owner and the caller's account are aligned.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.