Courseiva

SOA-C02 Deployment, Provisioning, and Automation Practice Question

Exhibit

Refer to the exhibit.
```json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:ListBucket",
      "Resource": "arn:aws:s3:::example-bucket"
    },
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*"
    }
  ]
}
```

An administrator attempts to deploy an application using AWS CodeDeploy. The deployment fails with 'Access Denied' when trying to download the revision from the S3 bucket 'example-bucket'. The IAM policy attached to the instance profile is shown in the exhibit. What is the cause of the failure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy is missing the s3:GetObjectVersion action for the bucket

The deployment fails with 'Access Denied' when trying to download the revision from S3. The IAM policy attached to the instance profile must allow the s3:GetObject action to download objects. However, if the deployment uses a specific version of the revision (e.g., when using CodeDeploy with S3 versioning), the s3:GetObjectVersion action is also required. The exhibit shows the policy includes s3:GetObject but not s3:GetObjectVersion, causing the failure. Option B is correct because the missing s3:GetObjectVersion action is the cause. Option A is incorrect because s3:ListBucket is present in the policy. Option C is incorrect because the policy does include s3:GetObject. Option D is incorrect because the policy is attached to the correct instance profile.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy does not include s3:ListBucket

    Why it's wrong here

    s3:ListBucket is only needed for listing the objects in a bucket, such as with ListObjectsV2, and it is not required to retrieve a known object by key. The deployment does not need to enumerate the bucket; it already knows the exact object key and version ID, so it issues a direct GetObjectVersion call. Moreover, the policy already includes s3:ListBucket, so any error related to listing permissions is not present; the failure is strictly caused by the missing version-specific read action.

  • ✓

    The policy is missing the s3:GetObjectVersion action for the bucket

    Why this is correct

    When you enable S3 Versioning, every object version has a unique versionId, and a GetObject request that specifies that version requires an explicit s3:GetObjectVersion permission in addition to s3:GetObject. The deployment workflow is calling GetObject with a versionId to fetch a unique revision, and the policy only grants the standard object-level actions. Without s3:GetObjectVersion, AWS rejects the request with AccessDenied, making this the exact root cause.

  • ✗

    The policy grants s3:ListBucket but not s3:GetObject

    Why it's wrong here

    The s3:GetObject action is already present in the policy and would permit a normal GetObject request for an object when no version ID is specified. However, when an application deploys from a versioned bucket and references a particular revision version, the underlying API call is GetObject with a versionId parameter, which requires both s3:GetObject and s3:GetObjectVersion. Because the error occurs on that version-aware request while GetObject is otherwise allowed, a missing GetObject action cannot be the cause.

  • ✗

    The policy is attached to the wrong IAM role

    Why it's wrong here

    If the policy were attached to the wrong IAM role, the instance profile would not pass any S3 permissions to the EC2 instance, and every S3 operation — including the initial steps of the deployment — would fail with AccessDenied. The fact that the failure occurs only when downloading the specific revision version shows the role already has ListBucket and GetObject, but not the version-level action. Since the error is permission-specific rather than universal, the role attachment is correct; the real issue is a missing s3:GetObjectVersion statement.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.