Alice can access both buckets because either an IAM or a bucket policy allows each with no explicit deny

Answer Correct answer: C — alice is allowed bucket1 by its bucket policy and bucket2 by her IAM policy; with no explicit deny she can access both.

An AWS account includes two S3 buckets: bucket1 and bucket2. The bucket2 does not have a policy defined, but bucket1 has the following bucket policy: In addition, the same account has an IAM User named “alice”, with the following IAM policy. Which buckets can user “alice” access? - image - image

  1. bucket1 only
  2. bucket2 only
  3. Both bucket1 and bucket2 Correct Answer
  4. Neither bucket1 nor bucket2

Community Votes

C
73%
B
27%

73% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

S3 authorization combines IAM policies and resource-based (bucket) policies: access is granted if either allows the action and there is no explicit deny anywhere. bucket1 is covered by its bucket policy allowing alice; bucket2 is covered by alice's identity policy allowing it. Because neither policy contains an explicit Deny, both grants stand and alice reaches both buckets.

bucket1 has a bucket policy that explicitly allows user alice access to bucket1/, and bucket2 has no bucket policy but alice's IAM policy allows access to bucket2/. In AWS, S3 access requires only one allowing permission (IAM or resource-based) and is blocked only by an explicit deny. With no explicit deny present, alice is permitted to bucket1 via its bucket policy and to bucket2 via her IAM policy, so she can access both.

Assuming both an IAM policy and a bucket policy must allow (they need not—either is sufficient), or assuming bucket2 is inaccessible just because it lacks a bucket policy (an IAM allow still grants access). An explicit deny would override, but none is present here.

Community Discussion (7 comments)

woonsi 👍 1 Selected: C
3️⃣ Combining Policies — How AWS evaluates this: AWS uses a combination of IAM policies and resource-based policies (like bucket policies). For Alice to access an S3 bucket: • Either the IAM policy or the bucket policy must allow the action (they don’t both need to allow it). • If one policy allows access and the other doesn’t mention it (or allows it too), access is granted. • Access is denied only if an explicit “Deny” exists in either policy — which isn’t present here. Since: • Bucket1’s policy allows Alice access. • Alice’s IAM policy allows access to bucket2. 👉 Alice can access both bucket1 and bucket2 — no conflicts or denies are present.
zhen234 👍 1 Selected: C
IAM policies are evaluated first. Bucket policies are evaluated after IAM policies. An explicit deny will override any allows. If there are no explicit denies, then an explicit allow will grant access.
m_ch333 👍 1 Selected: C
C. IAM policies and S3 bucket policies can both used for access control https://aws.amazon.com/blogs/security/iam-policies-and-bucket-policies-and-acls-oh-my-controlling-access-to-s3-resources/
SCSC02Q 👍 2 Selected: B
Its B since Alice's IAM policy only allows Bucket 2. Access to Bucket 1 will be denied unless this IAM Policy is updated.
IPLogic 👍 3 Selected: C
bucket1 has a policy that explicitly allows user "alice" access to arn:aws:s3:::bucket1/. bucket2 has no bucket policy, but "alice"’s IAM policy allows access to arn:aws:s3:::bucket2/. Here's the access situation: bucket1: User "alice" can access bucket1 because the bucket policy explicitly allows it. bucket2: User "alice" can access bucket2 because her IAM policy grants her permission to it, and there is no bucket policy to restrict this access. So, user "alice" can access both bucket1 and bucket2. Therefore, the correct answer is C. Both bucket1 and bucket2.
siheom 👍 2 Selected: C
it should be C https://www.examtopics.com/discussions/amazon/view/68809-exam-aws-certified-security-specialty-topic-1-question-89/
jdx000 👍 1 Selected: B
only bucket 2, so B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS evaluates S3 access by checking all applicable policies; an explicit allow in either the principal's IAM policy or the bucket policy is sufficient, and only an explicit Deny blocks. bucket1's bucket policy explicitly allows alice to bucket1/, and alice's IAM policy allows bucket2/. With no explicit deny in either, alice is authorized for both buckets.

Why the Other Options Are Wrong

A and B each ignore one of the two valid allow paths—bucket1 is reachable via its bucket policy and bucket2 via alice's IAM policy, so neither single-bucket answer is complete. D is wrong because there is no explicit deny; the presence of allows in either policy grants access.

Community Comment Notes

Community favored C (73 votes). Commenters explained that IAM and bucket policies are evaluated together, an allow in either suffices absent an explicit deny, and linked the IAM/bucket-policy evaluation blog. A minority argued B, misreading alice's IAM policy as bucket2-only and overlooking the bucket1 allow, but C reflects the correct combined evaluation. The policy texts appear in the question images; multiple commenters transcribed them as bucket1 allowing alice and alice's IAM allowing bucket2, with no explicit deny, which supports C.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide