CV0-004 Security Practice Question
A security engineer is configuring an AWS IAM policy for a new application. The policy must allow the application to read objects from a specific S3 bucket. Which IAM policy element determines whether the action is allowed or denied?
⚠ Common exam trap
The trap is confusing the roles of the four elements; candidates might think Action or Resource determines allow/deny, but only Effect explicitly sets the permission outcome.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Effect
The Effect element in an IAM policy specifies whether the statement allows or denies access. It is a required element that can be set to 'Allow' or 'Deny'. In this case, to allow the application to read objects, the Effect must be 'Allow'. Therefore, the Effect element determines whether the action is allowed or denied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Effect
Why this is correct
The Effect element specifies whether a matching statement results in Allow or Deny, making it the axis that determines the policy outcome. With the action and resource already scoped to s3:GetObject on the named bucket, Effect supplies the explicit Allow the stem requires.
- ✗
Action
Why it's wrong here
The Action element lists the operations the policy permits, such as s3:GetObject, but the Effect element is what states Allow or Deny. Action is tempting because it names the read operation, and it would be correct when specifying which S3 API calls the application may invoke.
- ✗
Resource
Why it's wrong here
The Resource element identifies the bucket or object ARN the statement covers, not whether access is granted. Resource is tempting because the stem names a specific bucket, and it would be correct for scoping the statement to that bucket's objects rather than all resources.
- ✗
Condition
Why it's wrong here
Condition elements only constrain when a statement applies, using operators such as StringEquals on keys; they cannot by themselves grant or deny access. Condition is tempting because it shapes policy evaluation, and it would be correct for restricting access by source IP or requiring MFA.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.