EC2 Instance Profile Missing — IAM Role Access Denied
Network Topology
Refer to the exhibit. An EC2 instance with an IAM role attached attempts to access an S3 bucket, but receives an 'AccessDenied' error. The role has an attached policy allowing s3:GetObject on the bucket. What is the most likely cause?
⚠ Common exam trap
SCS-C02 often tests the policy evaluation order, and the trap is assuming the IAM identity policy is the only relevant policy — candidates forget that an explicit Deny in a resource-based policy (like an S3 bucket policy) overrides any Allow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The S3 bucket policy denies access to the role.
When an IAM role has an identity-based policy allowing s3:GetObject but access is still denied, the most likely cause is an explicit Deny in the S3 bucket policy, because in AWS an explicit Deny anywhere in the evaluation chain overrides any Allow. The bucket policy is a resource-based policy evaluated alongside the identity-based policy, and a Deny there will block the role even though the IAM policy grants permission.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The S3 bucket policy denies access to the role.
Why this is correct
An explicit deny in the S3 bucket policy takes precedence over any allow granted by the IAM policy attached to the role. When the role attempts to access the bucket, S3 evaluates the bucket policy alongside the IAM policy; if it contains a Deny statement that applies to the role's ARN (or any principal that includes the role), the request fails with AccessDenied. This is the most direct cause here because the role and instance are otherwise correctly configured, isolating the issue to the resource policy.
- ✗
The IAM policy is not attached to the role.
Why it's wrong here
The question explicitly states that the IAM policy is attached to the role, so this option is factually incorrect. Even if the policy were missing, the instance would still obtain temporary credentials, but any S3 action would fail with AccessDenied for a different reason: the role would have no effective identity-based permissions to perform the request. A missing IAM policy would produce a broad lack of access across all services, whereas the error here points to a resource-specific denial from the bucket policy.
- ✗
The trust policy does not allow the EC2 service to assume the role.
Why it's wrong here
The trust policy controls which principals, including AWS services like EC2, are permitted to assume the role via STS. If EC2 were not allowed to assume the role, the instance would never receive temporary credentials at all, and the SDK would report a missing-credentials error or an explicit AssumeRole failure, not an S3 AccessDenied. Since the question states the role is attached to the instance and the error occurs during an S3 operation, the trust policy must already allow EC2 to assume the role.
- ✗
The EC2 instance does not have an instance profile associated with the role.
Why it's wrong here
An instance profile is the container that delivers the role to the EC2 instance; without it, the instance would not have temporary credentials in instance metadata and would fail before ever issuing an S3 request, typically with a 'unable to locate credentials' error. The presence of an AccessDenied response proves that credentials were successfully obtained and used, because the request reached S3 and was evaluated. Therefore, if the instance is running and using the role, the instance profile must be correctly associated.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.