Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A SysOps administrator needs to grant cross-account access to an S3 bucket in Account A for an IAM user in Account B. The bucket policy in Account A allows the IAM user's account root principal. What additional configuration is required?

⚠ Common exam trap

Many exam-takers assume the bucket policy alone is sufficient for cross-account access, forgetting that the IAM user in the target account must also have an explicit IAM policy allowing the S3 actions, as AWS requires both resource-based and identity-based permissions to be evaluated and both must allow the operation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an IAM policy to the user in Account B that allows the required S3 actions

D is correct because cross-account access to an S3 bucket requires both a bucket policy that grants access to the root principal of the target account (Account B) and an IAM policy attached to the user in Account B that explicitly allows the desired S3 actions. Without the IAM policy, the user in Account B has no permissions to perform any S3 operations, even though the bucket policy in Account A permits the account root. The IAM policy acts as the identity-based permission that authorizes the specific user to invoke the S3 API calls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the AWS KMS key policy to allow the user in Account B

    Why it's wrong here

    Changing the AWS KMS key policy is only required if the S3 bucket uses SSE-KMS encryption, and even then it must be paired with an IAM policy granting the user the necessary S3 actions. Since the question does not specify that the bucket is encrypted with SSE-KMS, this option is not the primary requirement. Moreover, modifying the key policy alone would not allow the user to access the bucket; the user still needs an identity-based policy. Therefore, this is not the correct answer.

  • ✗

    Add a bucket ACL granting access to the user in Account B

    Why it's wrong here

    Bucket ACLs are a legacy access control mechanism that only support a limited set of permissions and do not allow fine-grained actions such as GetObject or conditional policies. For cross-account access, AWS recommends using bucket policies and IAM policies rather than ACLs. Even if you add an ACL granting the user in Account B access, you still need an IAM policy in Account B that allows the S3 actions, so this option is incomplete and less secure. Therefore, it is not the correct approach.

  • ✗

    Add an AWS Organizations service control policy to allow access

    Why it's wrong here

    Service control policies (SCPs) in AWS Organizations are used to restrict the maximum available permissions for accounts in the organization; they never grant permissions. An SCP cannot allow a user to perform actions that are not already permitted by IAM or resource-based policies. Cross-account access is enabled by combining an IAM policy in the target account with a bucket policy in the source account. Thus, adding an SCP would not grant the user the required access and is incorrect.

  • ✓

    Attach an IAM policy to the user in Account B that allows the required S3 actions

    Why this is correct

    Attaching an IAM policy to the user in Account B is required because the user must have explicit permission to perform the S3 actions against the bucket in Account A. Even if Account A's bucket policy grants cross-account access to that user, the user's own IAM policy must also allow the actions, as permissions in AWS are effectively the intersection of the identity-based and resource-based policies. Without this IAM policy, the user will be denied access regardless of the bucket policy. Therefore, this is the correct necessary step.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.