SCS-C02 Management and Security Governance Practice Question
A security engineer needs to grant cross-account read access to an S3 bucket in Account A to a user in Account B. What is the correct combination of actions?
⚠ Common exam trap
Many candidates assume either a bucket policy alone or an IAM policy alone is sufficient for cross-account access, failing to recognize that AWS requires both the resource-based policy to grant access to the external principal and the identity-based policy to authorize the user to make the request.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a bucket policy in Account A granting access to the principal in Account B, and attach an IAM policy to the user in Account B allowing the action
Cross-account S3 access requires both a bucket policy in the resource account (Account A) that explicitly grants the cross-account principal (the user in Account B) the s3:GetObject action, and an IAM policy attached to the user in Account B that allows the same action. This two-way authorization is necessary because the bucket policy controls access to the S3 resource, while the IAM policy controls the user's permissions to initiate the request. Without both, the request will be denied by either the resource-based policy or the identity-based policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Attach an IAM policy to the user in Account B allowing the action; no bucket policy needed
Why it's wrong here
This approach is insufficient because S3 cross-account access requires an explicit resource-based policy on the bucket in Account A. An IAM policy attached to the user in Account B only defines the user's permissions within its own account, but it cannot authorize access to a resource owned by another account. By default, the bucket in Account A is private to Account A, so without a bucket policy that grants the Account B user (or its account) permission, the request is denied at the S3 service level. Thus, a user policy alone cannot enable cross-account reads.
- ✗
Apply a bucket policy in Account A granting access to the user in Account B; no user policy needed
Why it's wrong here
This option is incomplete because it omits the mandatory identity-based permission in Account B. While the bucket policy in Account A may explicitly grant access to the Account B user, IAM requires that for cross-account access, the principal's own account must also authorize the action. Even if the bucket policy allows s3:GetObject, the Account B user has no IAM policy allowing that action, so the request will be denied during IAM policy evaluation. The user in Account B must attach an IAM policy that permits the read action to complete the authorization chain.
- ✗
Use S3 bucket ACLs to grant READ access to the Account B user
Why it's wrong here
S3 bucket ACLs are a legacy authorization mechanism and are not the recommended way to grant cross-account access. ACLs do not support IAM roles, conditions, or many fine-grained permissions, and they still require the Account B user to have an IAM policy that allows the s3:GetObject action. Additionally, many S3 features (like bucket policies) are preferred over ACLs, and AWS discourages using ACLs except when you need to grant basic read/write permissions to specific AWS accounts. Therefore, relying solely on an ACL is both technically insufficient and an outdated approach for cross-account read access.
- ✓
Apply a bucket policy in Account A granting access to the principal in Account B, and attach an IAM policy to the user in Account B allowing the action
Why this is correct
This is the correct and complete solution. For cross-account S3 access, AWS requires that both the resource-based policy (bucket policy) in Account A and the identity-based policy (IAM policy) attached to the user in Account B explicitly allow the s3:GetObject action. The bucket policy grants the Account B principal access to the bucket, while the IAM policy provisions that principal with the necessary action permissions in its own account. Without either side, the request is denied. This dual-policy requirement ensures both the resource owner and the caller's account are aligned.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.