Refer to the exhibit. An IAM policy is attached to a user. Which action is the user allowed to perform?
The policy grants s3:GetObject on the bucket's objects, so the user can retrieve existing objects. It does not permit s3:PutObject or s3:DeleteObject, so writing or removing objects is denied. Reading an existing object is therefore the only allowed action.
Why this answer
The IAM policy grants the `s3:GetObject` action, which allows the user to read (download) an existing object from the specified S3 bucket. The policy explicitly allows this action for the bucket `my-bucket` and its objects, so the user can perform read operations on objects within that bucket.
Exam trap
ISC2 often tests the distinction between read and write permissions in S3 policies, where candidates mistakenly assume that `s3:GetObject` implies the ability to upload or modify objects, but each action (Get, Put, Delete) must be explicitly granted.
How to eliminate wrong answers
Option A is wrong because changing a bucket's policy requires the `s3:PutBucketPolicy` action, which is not included in the attached policy. Option C is wrong because uploading a new object requires the `s3:PutObject` action, which is not granted by the policy. Option D is wrong because deleting an object requires the `s3:DeleteObject` action, which is also absent from the policy.