Alice can access both buckets because either an IAM or a bucket policy allows each with no explicit deny
An AWS account includes two S3 buckets: bucket1 and bucket2. The bucket2 does not have a policy defined, but bucket1 has the following bucket policy: In addition, the same account has an IAM User named “alice”, with the following IAM policy. Which buckets can user “alice” access? -
- 
Community Votes
73% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
S3 authorization combines IAM policies and resource-based (bucket) policies: access is granted if either allows the action and there is no explicit deny anywhere. bucket1 is covered by its bucket policy allowing alice; bucket2 is covered by alice's identity policy allowing it. Because neither policy contains an explicit Deny, both grants stand and alice reaches both buckets.
bucket1 has a bucket policy that explicitly allows user alice access to bucket1/, and bucket2 has no bucket policy but alice's IAM policy allows access to bucket2/. In AWS, S3 access requires only one allowing permission (IAM or resource-based) and is blocked only by an explicit deny. With no explicit deny present, alice is permitted to bucket1 via its bucket policy and to bucket2 via her IAM policy, so she can access both.
Assuming both an IAM policy and a bucket policy must allow (they need not—either is sufficient), or assuming bucket2 is inaccessible just because it lacks a bucket policy (an IAM allow still grants access). An explicit deny would override, but none is present here.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.