SOA-C02 Security and Compliance Practice Question
A SysOps administrator is troubleshooting an issue where an EC2 instance cannot access an S3 bucket using an instance profile. The instance profile has an IAM role with a policy that allows s3:GetObject on the bucket. The S3 bucket policy has a Deny for all principals except a specific service role. What is the most likely reason for the access failure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The S3 bucket policy Deny overrides the IAM role permissions.
An explicit Deny in an S3 bucket policy overrides any Allow permissions granted by IAM policies, including those from an instance profile role. In this scenario, the bucket policy denies access to all principals except a specific service role, so even though the IAM role attached to the EC2 instance allows s3:GetObject, the Deny takes precedence, causing access failure. Option A is incorrect because the issue is not about the trust policy; if the instance profile is attached, EC2 can assume the role. Option B is incorrect because the instance profile attachment is not the likely cause; the Deny in the bucket policy would block access regardless. Option C is incorrect because a VPC endpoint is not required for S3 access and would not override the bucket policy Deny.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IAM role trust policy does not allow EC2 to assume the role.
Why it's wrong here
If the EC2 trust policy did not allow the ec2.amazonaws.com service principal, the instance would fail to retrieve temporary credentials from the instance metadata service, causing errors such as 'Unable to locate credentials' or 'AccessDenied' from the STS API itself. However, the scenario states the trust policy is configured correctly, and the troubleshooting is occurring because the instance successfully obtained a role and made S3 requests that were explicitly rejected. Therefore, the failure lies in S3 authorization, not in role assumption.
- ✗
The instance profile is not correctly attached to the EC2 instance.
Why it's wrong here
An instance profile that is not attached, or that lacks the correct IAM role, would prevent the EC2 instance from receiving any temporary security credentials, resulting in a 'NoCredentialProviders' or 'CredentialsNotFoundError' when the AWS CLI tries to call S3. Since the instance is already using the intended role and the access failure is an S3 AccessDenied response, the instance profile attachment is not the root cause. The error occurs after authentication, meaning the credential acquisition path is functioning normally.
- ✗
The S3 bucket requires a VPC endpoint.
Why it's wrong here
A VPC endpoint for S3 is only required when you want private connectivity between an EC2 instance and S3 without traffic traversing the public internet or a NAT gateway. There is no default requirement that all S3 access must come through a VPC endpoint, and IAM-based access over the public S3 endpoint works fine when the bucket policy allows it. Here, the bucket policy contains an explicit Deny, which would still apply regardless of whether traffic arrives via a VPC endpoint, a NAT gateway, or the public internet, so the VPC endpoint is irrelevant to the authorization failure.
- ✓
The S3 bucket policy Deny overrides the IAM role permissions.
Why this is correct
When both an IAM role policy and a bucket policy apply to the same S3 request, AWS evaluates all identity-based and resource-based policies, and an explicit Deny in any applicable policy takes precedence over any Allow. In this scenario, the IAM role grants the s3:GetObject permission, but the S3 bucket policy contains a separate statement that explicitly denies the same action; the explicit Deny overrides the allow and causes the final authorization decision to be Deny AWS documentation confirms that explicit deny statements in resource policies are authoritative and cannot be overridden by any other allow. Therefore, the bucket policy Deny is the reason the EC2 instance cannot access the object.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.