Courseiva
Security and ComplianceeasyMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company stores sensitive financial data in an Amazon S3 bucket. The security policy requires that all data must be encrypted in transit. The security administrator discovers that some automated scripts are using HTTP instead of HTTPS to upload files. The administrator must enforce that any request that does not use HTTPS is denied by the S3 bucket policy. Which condition key should the administrator include in the bucket policy to enforce this requirement?

⚠ Common exam trap

Candidates often confuse `aws:SecureTransport` with other condition keys like `aws:SourceIp` or `aws:Referer`, which control different aspects of access (network origin or referrer) rather than the transport protocol itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

aws:SecureTransport

The `aws:SecureTransport` condition key in an S3 bucket policy evaluates whether the request was sent over HTTPS (TLS). Setting it to `false` denies any request that uses HTTP, enforcing encryption in transit as required by the security policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • aws:SourceIp

    Why it's wrong here

    `aws:SourceIp` is a global IAM condition key that compares the requester's IP address to the allowed values in the policy, enabling IP-based allowlists or denylists for API calls. It acts purely at the network layer by inspecting where the request originates, which could be a public IP, a VPC IP, or even a spoofed source—it never inspects whether that connection was encrypted with TLS. A source IP allowlist can restrict who can reach the bucket, but it says nothing about how the data travels, so a user from an approved IP could still send requests via unencrypted HTTP.

    When this WOULD be correct

    A company wants to allow S3 bucket access only from a specific corporate IP range to prevent unauthorized access from outside the network. The bucket policy would use aws:SourceIp to deny requests from IPs outside that range.

  • aws:Referer

    Why it's wrong here

    `aws:Referer` evaluates the HTTP `Referer` header, which the client sends (often automatically from a browser) to indicate the URL of the page that linked to the request. This condition key is commonly used to prevent hotlinking by limiting access to S3 objects from specific external websites, but the header is trivial to forge or omit and does not represent any security credential or protocol property. It only inspects application-layer metadata about the previous page, not whether the current request was made over HTTPS, so it cannot enforce encryption in transit.

    When this WOULD be correct

    A company wants to restrict access to an S3 bucket so that only requests originating from a specific website (e.g., a corporate web application) are allowed. The administrator would use the aws:Referer condition key to deny requests that do not include the expected Referer header.

  • aws:SecureTransport

    Why this is correct

    This condition key checks if the request was sent over SSL/TLS. When set to 'false', the condition matches HTTP requests, allowing the policy to deny them. This is the correct key to enforce encryption in transit.

  • s3:x-amz-server-side-encryption

    Why it's wrong here

    The `s3:x-amz-server-side-encryption` condition key checks the value of the `x-amz-server-side-encryption` header in the request, typically to require AES256 or `aws:kms` encryption for objects as they are written to S3. This enforces encryption at rest—how the object is stored on S3's managed disks—but it does not evaluate the connection between the client and S3. The key inspects a request header, not the TLS state of the transport session, so it cannot prevent data from being sent over plaintext HTTP during the upload.

    When this WOULD be correct

    A company requires that all objects uploaded to an S3 bucket must be encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). The bucket policy should deny any PutObject request that does not include the x-amz-server-side-encryption header with value aws:kms.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

aws:SecureTransportCorrect answer

Why this is correct

This condition key checks if the request was sent over SSL/TLS. When set to 'false', the condition matches HTTP requests, allowing the policy to deny them. This is the correct key to enforce encryption in transit.

aws:SourceIpWrong answer — click to see why

Why this is wrong here

The aws:SourceIp condition key restricts access based on IP address, not on whether the connection uses HTTPS. It cannot enforce encryption in transit.

★ When this WOULD be the correct answer

A company wants to allow S3 bucket access only from a specific corporate IP range to prevent unauthorized access from outside the network. The bucket policy would use aws:SourceIp to deny requests from IPs outside that range.

Why candidates choose this

Candidates may mistakenly think that restricting access by IP address can enforce secure connections, or they confuse network-level controls with transport encryption requirements.

aws:RefererWrong answer — click to see why

Why this is wrong here

The aws:Referer condition key checks the HTTP Referer header, which is used to identify the web page that linked to the requested resource. It does not enforce encryption in transit; it is used to prevent unauthorized cross-site requests or hotlinking.

★ When this WOULD be the correct answer

A company wants to restrict access to an S3 bucket so that only requests originating from a specific website (e.g., a corporate web application) are allowed. The administrator would use the aws:Referer condition key to deny requests that do not include the expected Referer header.

Why candidates choose this

Candidates may confuse referer with security mechanisms, thinking it can enforce HTTPS because it involves HTTP headers, but it actually controls request origin, not transport encryption.

s3:x-amz-server-side-encryptionWrong answer — click to see why

Why this is wrong here

The s3:x-amz-server-side-encryption condition key enforces server-side encryption at rest, not encryption in transit. The question specifically requires encryption in transit (HTTPS), which is controlled by aws:SecureTransport.

★ When this WOULD be the correct answer

A company requires that all objects uploaded to an S3 bucket must be encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). The bucket policy should deny any PutObject request that does not include the x-amz-server-side-encryption header with value aws:kms.

Why candidates choose this

Candidates may confuse encryption in transit with encryption at rest, or think that server-side encryption covers all encryption requirements. The option sounds security-related and appears to enforce encryption, leading to a mistaken choice.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.