Why Explicit Deny in S3 Bucket Policy Overrides IAM Allow
A developer is trying to use the AWS CLI to list objects in an S3 bucket but receives an AccessDenied error. The developer has an IAM user with a policy that allows s3:ListBucket on the bucket. What could be causing the error?
⚠ Common exam trap
SCS-C02 often tests the misconception that an IAM Allow is sufficient for S3 access, when in fact an explicit Deny in a bucket policy, SCP, or permission boundary silently overrides it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The S3 bucket has a bucket policy that denies access to the developer's IAM user.
S3 access decisions are evaluated by combining IAM identity-based policies with bucket policies, and an explicit Deny in either location always wins. Even though the developer's IAM policy grants s3:ListBucket, a bucket policy that explicitly denies the user's principal overrides that Allow. This is the classic 'explicit deny beats allow' rule in AWS's policy evaluation logic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The developer has not enabled MFA on their IAM user.
Why it's wrong here
AWS does not require MFA for S3 API operations just because a user has an IAM user; MFA is only considered when a policy explicitly includes a condition such as `aws:MultiFactorAuthPresent: "true"`. Without such a condition in either the IAM policy or the bucket policy, the absence of an MFA device or a one-time passcode is not evaluated and cannot cause an AccessDenied error. Therefore, this option is not a plausible root cause for the CLI failure.
- ✓
The S3 bucket has a bucket policy that denies access to the developer's IAM user.
Why this is correct
An explicit deny statement in a bucket policy always overrides any allow granted by an IAM policy, regardless of how specific or broad that allow is. Here, even if the developer's IAM user is explicitly allowed `s3:ListBucket` by an identity-based policy, a bucket policy that contains a matching `Effect: "Deny"` for that principal (or a deny condition that matches the user) will make the request fail with AccessDenied. This is the only option that explains a denied request despite valid credentials and an otherwise permissive IAM setup.
- ✗
The S3 bucket does not exist in the same AWS region as the CLI is configured.
Why it's wrong here
Amazon S3 is a regional service, but a bucket name is globally unique and API calls are routed based on the bucket's actual location, not the CLI's configured region. If the CLI were targeting a bucket in another region, the request would succeed normally because S3 automatically handles the backend region; a region mismatch might produce a redirect or a bucket-region error, but never an AccessDenied. The fact that the error is AccessDenied indicates the bucket exists and the request was authenticated, but the principal was not authorized, which is unrelated to region configuration.
- ✗
The IAM policy is attached to a group, not directly to the user.
Why it's wrong here
IAM policies attached to a group are inherited by all members of the group, so the developer's effective permissions include both the group-attached policy and any user-attached policies. This inheritance grants permissions rather than restricting them, so the policy being attached to a group does not by itself cause an AccessDenied. If the developer lacked the necessary `s3:ListBucket` permission, it would mean that neither the group policy nor the user policy granted the action, but that would be a simple absence of an allow—not an explicit deny, and not specifically caused by group attachment.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.