CompTIA Cloud+ (CV0-004)TroubleshootingHard

A cloud engineer is investigating an application that allows users to upload large files to an object storage bucket. Users are reporting occasional 'Access Denied' errors during the upload process, even though the IAM policy for the application's service account explicitly grants `s3:PutObject` and `s3:GetObject` permissions to the target bucket. The bucket also has a policy that denies uploads of objects larger than 5GB. What is the MOST likely cause of the 'Access Denied' errors?

  1. AThe object storage bucket has versioning enabled, conflicting with upload permissions.
  2. BThe application's service account is missing `s3:PutObjectAcl` permission.
  3. CThe bucket policy's size restriction is being enforced, leading to an 'Access Denied' error.
  4. DThe user's network connection is unstable, causing intermittent upload failures.
Show answer & explanation

Correct answer: C. The bucket policy's size restriction is being enforced, leading to an 'Access Denied' error.

Cloud object storage services often enforce bucket policies with conditions, such as object size limits. When an upload exceeds such a limit, the service will deny the request. Even though the IAM policy grants `PutObject`, the bucket policy's explicit deny (or condition-based deny) for oversized objects takes precedence, resulting in an 'Access Denied' error.

Why the other options are wrong

  • A. Versioning enabled on a bucket generally works seamlessly with `PutObject` operations, creating new versions. It doesn't typically conflict with basic upload permissions or cause 'Access Denied' errors for successful uploads.
  • B. `s3:PutObjectAcl` is for setting ACLs on objects, not for the act of uploading the object itself. Its absence would not typically cause general 'Access Denied' on `PutObject`.
  • D. Unstable network connections would typically result in connection timeouts, partial uploads, or specific network errors, not an 'Access Denied' message from the object storage service itself.

Object Storage Bucket Policy Conditions

Conditional statements within an object storage bucket policy that allow or deny actions based on specific criteria, such as object size, content type, or encryption status.

  • Provides fine-grained control over actions on objects.
  • Conditions can override general IAM permissions if met.
  • Often used for security (e.g., encryption enforcement) or operational limits (e.g., max object size).

Memory trick: Your ID says you can enter, but the size limit sign says 'No big packages!'

More Troubleshooting questions