Courseiva

SOA-C02 Reliability and Business Continuity Practice Question

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:PutObject",
      "Resource": "arn:aws:s3:::my-bucket/*"
    }
  ]
}
```

Refer to the exhibit. A SysOps administrator creates an IAM policy to allow an EC2 instance to upload objects to an S3 bucket. However, the instance is unable to upload objects. What is the MOST likely reason?

⚠ Common exam trap

Test-takers frequently assume the IAM policy alone is sufficient, forgetting that the EC2 instance must have a mechanism (the instance profile) to assume the role and obtain credentials.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IAM role is not attached to the EC2 instance.

The IAM role must be attached to the EC2 instance as an instance profile for the instance to assume the role and obtain temporary credentials. Without this attachment, the instance has no valid AWS credentials to sign API requests, so the s3:PutObject action will fail regardless of the permissions defined in the role's policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The S3 bucket has server-side encryption enabled.

    Why it's wrong here

    Server-side encryption (SSE) protects data at rest in S3, but it has no effect on the IAM authorization process for uploading objects. When an EC2 instance attempts an s3:PutObject, S3 checks the caller's IAM identity (or the bucket policy) for the required permission before considering encryption settings. An encrypted bucket still accepts uploads from any principal with valid write permissions, so enabling SSE does not block the upload; it only encrypts the object after the request is authorized.

  • ✗

    The policy does not include s3:GetObject permission.

    Why it's wrong here

    The s3:GetObject permission grants read access to objects, whereas the upload operation requires s3:PutObject. The IAM policy attached to the role would need s3:PutObject (and possibly s3:ListBucket for some APIs), but the failure to upload is not due to a missing read permission. If anything, the policy might be missing s3:PutObject, but the question specifically indicates GetObject is not needed. Thus, the absence of GetObject alone would not prevent the upload; an upload would succeed with only PutObject permission.

  • ✗

    The bucket policy denies all access.

    Why it's wrong here

    The exhibit does not show any bucket policy that explicitly denies all access. An S3 bucket can have a bucket policy that overrides IAM permissions, but without evidence of such a policy, we cannot attribute the failure to that cause. Moreover, a bucket policy that denies all access would produce an AccessDenied error for any principal, but the actual cause here is that the instance has no IAM role at all. Since no bucket policy is present in the exhibit, this option is unsupported and incorrect.

  • ✓

    The IAM role is not attached to the EC2 instance.

    Why this is correct

    An EC2 instance can only use IAM permissions if an instance profile containing a role is attached at launch time or later. Without an attached role, the instance has no AWS credentials to sign API requests, so any S3 operation (including upload) fails with an error such as 'Unable to locate credentials' or an access denied error because the request is not authenticated with an authorized IAM identity. The role must be attached to the EC2 instance and the instance must have the necessary permissions in its trust and permissions policies. This is the root cause of the upload failure.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.