SOA-C02 Security and Compliance Practice Question
A company uses an IAM policy that allows s3:GetObject for a specific bucket. However, an IAM user is getting an Access Denied error when trying to download an object. The bucket policy also allows s3:GetObject for the user's account. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The bucket policy has a Deny statement that applies to the user.
The most likely cause because if the bucket policy has a Deny statement that applies to the user, that explicit denial overrides any allow from the IAM policy or the bucket policy. Option A is incorrect because s3:GetObjectVersion is not required to download the current version; s3:GetObject is sufficient. Option C is incorrect because there is no indication that the object is encrypted with KMS, and even if it were, the error would be different (e.g., 'AccessDenied' due to missing KMS permissions, but the scenario explicitly says Access Denied from S3). Option D is incorrect because SCPs apply to the entire account, but the question states that both IAM and bucket policies allow access, so an SCP denial would be possible, but it is not the most likely cause given the explicit allow statements and the fact that a bucket-level Deny is more direct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IAM policy does not include the s3:GetObjectVersion action.
Why it's wrong here
The s3:GetObjectVersion action is specifically required to retrieve a particular version of an object in a versioned bucket; it is not needed for a standard GET request that operates on the current object version. A standard GetObject call only requires the s3:GetObject permission. Therefore, omitting GetObjectVersion from the IAM policy cannot prevent a successful GetObject, making this explanation incorrect for the observed failure.
- ✓
The bucket policy has a Deny statement that applies to the user.
Why this is correct
An explicit Deny statement in a bucket policy always overrides any Allow that exists in an IAM identity-based policy, because AWS IAM evaluates all policies and the explicit deny takes precedence. If the bucket policy contains a Deny that applies to this specific user, the user will receive AccessDenied even if their IAM policy grants s3:GetObject for the same bucket and object. This is the classic cause described in the scenario, and it correctly explains why the user is blocked.
- ✗
The object is encrypted with a customer-managed KMS key, and the user does not have kms:Decrypt permissions.
Why it's wrong here
For an object encrypted with a customer-managed KMS key, the s3:GetObject API call requires the caller to have kms:Decrypt permission on that key, in addition to s3:GetObject. However, the question does not state that the object is encrypted, and assuming encryption just to explain the error is unsupported. If the object were not encrypted, this explanation would not apply; also, even with encryption, a bucket policy Deny would still be evaluated first and cause the same failure. Thus, while this is a plausible access-denied cause in other contexts, it is not the correct cause here.
- ✗
The user's account is part of an AWS Organization with an SCP that denies s3:GetObject.
Why it's wrong here
AWS Organizations Service Control Policies (SCPs) provide account-level controls and can deny s3:GetObject, but they affect every principal in the member account, not just one user. The scenario indicates the user is in the same account as the bucket, and there is no mention of an organization or SCP that would restrict this action. If such an SCP denied s3:GetObject, it would appear as a blanket denial across the account, but the problem points to a user-specific bucket policy Deny as the actual mechanism. Therefore, this explanation does not match the details given.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.