Courseiva

SCS-C02 Identity and Access Management Practice Question

An IAM policy has the following statement: {"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::my-bucket/*"}. A user with this policy tries to perform s3:ListBucket on 'my-bucket'. Will the request succeed?

⚠ Common exam trap

SCS-C02 often tests the misconception that s3:* on a bucket/* ARN grants all S3 actions on the bucket, but bucket-level actions require the bucket ARN without the wildcard.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No, because the resource ARN does not include the bucket itself.

The statement grants s3:* on arn:aws:s3:::my-bucket/*, which matches only objects inside the bucket, not the bucket itself. s3:ListBucket is a bucket-level operation that requires the resource arn:aws:s3:::my-bucket (without the /*). Since the policy does not grant access to that resource, the request is denied by default. This is a classic IAM resource-ARN mismatch.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    No, because there is an explicit deny elsewhere.

    Why it's wrong here

    This answer misattributes the failure to an explicit deny. In IAM, an explicit deny in a separate policy would override allows, but the scenario presents only an allow statement and gives no mention of any deny statement; the inability to list the bucket arises from the allow statement's resource scope, not from a conflicting denial. IAM's default-deny behavior might superficially look like an explicit deny, but default deny is just the absence of an allow, which is not the same as the final decision being caused by an explicit deny.

  • ✗

    Yes, because s3:* allows all actions.

    Why it's wrong here

    While s3:* does enumerate every Amazon S3 action, the action element alone is not sufficient to grant the request. The statement also constrains the Resource to an object-level ARN pattern such as arn:aws:s3:::bucket/*, and s3:ListBucket is evaluated against the bucket ARN (arn:aws:s3:::bucket), which is not matched by that pattern. Therefore, even a wildcard action set cannot override the resource restriction.

  • ✓

    No, because the resource ARN does not include the bucket itself.

    Why this is correct

    s3:ListBucket is a bucket-level action, so IAM evaluates the Resource against the bucket's ARN (arn:aws:s3:::bucket), not the ARN of objects inside it. A resource pattern that includes only the wildcard for object keys (e.g., arn:aws:s3:::bucket/*) does not match the bucket ARN, because the bucket itself is a distinct resource. Consequently, the allow statement does not cover this request, and the user cannot list the bucket.

  • ✗

    Yes, because the user has permission to access objects.

    Why it's wrong here

    Having permission to access objects (for example, through s3:GetObject or s3:PutObject) only authorizes operations that target the object resource type, such as reading or writing a specific key. Listing a bucket is an operation on the bucket resource type, so it requires an allow on the bucket ARN for s3:ListBucket. Object-level permissions are orthogonal to bucket-level permissions, so this rationale incorrectly conflates the two resource scopes.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.