DVA-C02 Security Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenyNonHttps",
"Effect": "Deny",
"Principal": "*",
"Action": "s3:*",
"Resource": [
"arn:aws:s3:::my-bucket",
"arn:aws:s3:::my-bucket/*"
],
"Condition": {
"Bool": {
"aws:SecureTransport": "false"
}
}
}
]
}A developer applied the above bucket policy to an S3 bucket. What is the outcome?
⚠ Common exam trap
Many exam-takers think a `Deny` statement with a condition is ineffective or only applies to specific actions, but in reality, the `Deny` with `StringNotEquals` on `aws:SecureTransport` explicitly blocks all non-HTTPS requests, making it a powerful enforcement mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All requests to the bucket must use HTTPS; otherwise, they are denied.
The bucket policy includes a `Deny` effect with a `StringNotEquals` condition on `aws:SecureTransport`, which denies any request that does not use HTTPS. Since the `Principal` is set to `*`, this applies to all users, including anonymous users. Therefore, any request made over HTTP is denied, effectively requiring HTTPS for all access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Anonymous users are allowed to read objects.
Why it's wrong here
This statement is incorrect because the bucket policy contains an explicit `Deny` effect for all S3 actions (`s3:*`) for all principals (`*`) when the `aws:SecureTransport` condition is false. This means that anonymous users attempting to read objects without HTTPS will be explicitly denied. Even with HTTPS, this policy does not grant any `Allow` permissions for anonymous users; it only prevents the denial from applying.
- ✗
Only write requests are denied if not using HTTPS.
Why it's wrong here
This statement is incorrect because the `Action` element in the bucket policy is `s3:*`, which represents all possible S3 actions, not just write requests. This broad action scope includes read operations (e.g., `s3:GetObject`), delete operations (e.g., `s3:DeleteObject`), and various other management actions. Therefore, any request, regardless of its type, will be denied if it does not use HTTPS.
- ✓
All requests to the bucket must use HTTPS; otherwise, they are denied.
Why this is correct
This statement is correct. The bucket policy uses an `Effect: Deny` combined with a `Condition` that `aws:SecureTransport` is `false`. This configuration explicitly blocks any request made to the S3 bucket that does not utilize HTTPS encryption. Consequently, all successful interactions with the bucket must occur over a secure transport layer, enforcing HTTPS for data in transit.
- ✗
The policy has no effect because it uses Deny.
Why it's wrong here
This statement is incorrect. `Deny` statements in AWS IAM and S3 bucket policies are extremely effective and always take precedence over `Allow` statements. If a `Deny` condition is met, the request is rejected, irrespective of any `Allow` policies that might also apply. This policy will successfully prevent any non-HTTPS access to the bucket.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DVA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A developer attaches the above S3 bucket policy to my-bucket. A user tries to upload an object using HTTP (not HTTPS). What will happen?
hard- A.The upload succeeds because the Deny effect only applies if the condition is true
- B.The upload succeeds if the user also has an Allow in another policy
- ✓ C.The upload is denied
- D.The upload succeeds because there is no Allow statement
Why C: The bucket policy includes a Deny effect for requests where aws:SecureTransport is false (i.e., HTTP). Since the user is uploading via HTTP, the condition is true, so the Deny statement applies and the upload is denied. Explicit Deny always overrides any Allow.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.