CLF-C02 Security and Compliance Practice Question
A company stores sensitive financial data in an Amazon S3 bucket. The security policy requires that all data must be encrypted in transit. The security administrator discovers that some automated scripts are using HTTP instead of HTTPS to upload files. The administrator must enforce that any request that does not use HTTPS is denied by the S3 bucket policy. Which condition key should the administrator include in the bucket policy to enforce this requirement?
⚠ Common exam trap
Candidates often confuse `aws:SecureTransport` with other condition keys like `aws:SourceIp` or `aws:Referer`, which control different aspects of access (network origin or referrer) rather than the transport protocol itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aws:SecureTransport
The `aws:SecureTransport` condition key in an S3 bucket policy evaluates whether the request was sent over HTTPS (TLS). Setting it to `false` denies any request that uses HTTP, enforcing encryption in transit as required by the security policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aws:SourceIp
Why it's wrong here
`aws:SourceIp` is a global IAM condition key that compares the requester's IP address to the allowed values in the policy, enabling IP-based allowlists or denylists for API calls. It acts purely at the network layer by inspecting where the request originates, which could be a public IP, a VPC IP, or even a spoofed source—it never inspects whether that connection was encrypted with TLS. A source IP allowlist can restrict who can reach the bucket, but it says nothing about how the data travels, so a user from an approved IP could still send requests via unencrypted HTTP.
When this WOULD be correct
A company wants to allow S3 bucket access only from a specific corporate IP range to prevent unauthorized access from outside the network. The bucket policy would use aws:SourceIp to deny requests from IPs outside that range.
- ✗
aws:Referer
Why it's wrong here
`aws:Referer` evaluates the HTTP `Referer` header, which the client sends (often automatically from a browser) to indicate the URL of the page that linked to the request. This condition key is commonly used to prevent hotlinking by limiting access to S3 objects from specific external websites, but the header is trivial to forge or omit and does not represent any security credential or protocol property. It only inspects application-layer metadata about the previous page, not whether the current request was made over HTTPS, so it cannot enforce encryption in transit.
When this WOULD be correct
A company wants to restrict access to an S3 bucket so that only requests originating from a specific website (e.g., a corporate web application) are allowed. The administrator would use the aws:Referer condition key to deny requests that do not include the expected Referer header.
- ✓
aws:SecureTransport
Why this is correct
This condition key checks if the request was sent over SSL/TLS. When set to 'false', the condition matches HTTP requests, allowing the policy to deny them. This is the correct key to enforce encryption in transit.
- ✗
s3:x-amz-server-side-encryption
Why it's wrong here
The `s3:x-amz-server-side-encryption` condition key checks the value of the `x-amz-server-side-encryption` header in the request, typically to require AES256 or `aws:kms` encryption for objects as they are written to S3. This enforces encryption at rest—how the object is stored on S3's managed disks—but it does not evaluate the connection between the client and S3. The key inspects a request header, not the TLS state of the transport session, so it cannot prevent data from being sent over plaintext HTTP during the upload.
When this WOULD be correct
A company requires that all objects uploaded to an S3 bucket must be encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). The bucket policy should deny any PutObject request that does not include the x-amz-server-side-encryption header with value aws:kms.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓aws:SecureTransportCorrect answer▾
Why this is correct
This condition key checks if the request was sent over SSL/TLS. When set to 'false', the condition matches HTTP requests, allowing the policy to deny them. This is the correct key to enforce encryption in transit.
✗aws:SourceIpWrong answer — click to see why▾
Why this is wrong here
The aws:SourceIp condition key restricts access based on IP address, not on whether the connection uses HTTPS. It cannot enforce encryption in transit.
★ When this WOULD be the correct answer
A company wants to allow S3 bucket access only from a specific corporate IP range to prevent unauthorized access from outside the network. The bucket policy would use aws:SourceIp to deny requests from IPs outside that range.
Why candidates choose this
Candidates may mistakenly think that restricting access by IP address can enforce secure connections, or they confuse network-level controls with transport encryption requirements.
✗aws:RefererWrong answer — click to see why▾
Why this is wrong here
The aws:Referer condition key checks the HTTP Referer header, which is used to identify the web page that linked to the requested resource. It does not enforce encryption in transit; it is used to prevent unauthorized cross-site requests or hotlinking.
★ When this WOULD be the correct answer
A company wants to restrict access to an S3 bucket so that only requests originating from a specific website (e.g., a corporate web application) are allowed. The administrator would use the aws:Referer condition key to deny requests that do not include the expected Referer header.
Why candidates choose this
Candidates may confuse referer with security mechanisms, thinking it can enforce HTTPS because it involves HTTP headers, but it actually controls request origin, not transport encryption.
✗s3:x-amz-server-side-encryptionWrong answer — click to see why▾
Why this is wrong here
The s3:x-amz-server-side-encryption condition key enforces server-side encryption at rest, not encryption in transit. The question specifically requires encryption in transit (HTTPS), which is controlled by aws:SecureTransport.
★ When this WOULD be the correct answer
A company requires that all objects uploaded to an S3 bucket must be encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). The bucket policy should deny any PutObject request that does not include the x-amz-server-side-encryption header with value aws:kms.
Why candidates choose this
Candidates may confuse encryption in transit with encryption at rest, or think that server-side encryption covers all encryption requirements. The option sounds security-related and appears to enforce encryption, leading to a mistaken choice.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.