SOA-C02 Reliability and Business Continuity Practice Question
Exhibit
Refer to the exhibit.
```
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:PutObject",
"Resource": "arn:aws:s3:::my-bucket/*"
}
]
}
```Refer to the exhibit. A SysOps administrator creates an IAM policy to allow an EC2 instance to upload objects to an S3 bucket. However, the instance is unable to upload objects. What is the MOST likely reason?
⚠ Common exam trap
Test-takers frequently assume the IAM policy alone is sufficient, forgetting that the EC2 instance must have a mechanism (the instance profile) to assume the role and obtain credentials.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IAM role is not attached to the EC2 instance.
The IAM role must be attached to the EC2 instance as an instance profile for the instance to assume the role and obtain temporary credentials. Without this attachment, the instance has no valid AWS credentials to sign API requests, so the s3:PutObject action will fail regardless of the permissions defined in the role's policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The S3 bucket has server-side encryption enabled.
Why it's wrong here
Server-side encryption (SSE) protects data at rest in S3, but it has no effect on the IAM authorization process for uploading objects. When an EC2 instance attempts an s3:PutObject, S3 checks the caller's IAM identity (or the bucket policy) for the required permission before considering encryption settings. An encrypted bucket still accepts uploads from any principal with valid write permissions, so enabling SSE does not block the upload; it only encrypts the object after the request is authorized.
- ✗
The policy does not include s3:GetObject permission.
Why it's wrong here
The s3:GetObject permission grants read access to objects, whereas the upload operation requires s3:PutObject. The IAM policy attached to the role would need s3:PutObject (and possibly s3:ListBucket for some APIs), but the failure to upload is not due to a missing read permission. If anything, the policy might be missing s3:PutObject, but the question specifically indicates GetObject is not needed. Thus, the absence of GetObject alone would not prevent the upload; an upload would succeed with only PutObject permission.
- ✗
The bucket policy denies all access.
Why it's wrong here
The exhibit does not show any bucket policy that explicitly denies all access. An S3 bucket can have a bucket policy that overrides IAM permissions, but without evidence of such a policy, we cannot attribute the failure to that cause. Moreover, a bucket policy that denies all access would produce an AccessDenied error for any principal, but the actual cause here is that the instance has no IAM role at all. Since no bucket policy is present in the exhibit, this option is unsupported and incorrect.
- ✓
The IAM role is not attached to the EC2 instance.
Why this is correct
An EC2 instance can only use IAM permissions if an instance profile containing a role is attached at launch time or later. Without an attached role, the instance has no AWS credentials to sign API requests, so any S3 operation (including upload) fails with an error such as 'Unable to locate credentials' or an access denied error because the request is not authenticated with an authorized IAM identity. The role must be attached to the EC2 instance and the instance must have the necessary permissions in its trust and permissions policies. This is the root cause of the upload failure.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.