A developer wants to ensure that an S3 bucket only allows HTTPS requests. What S3 bucket policy condition should be used?
The aws:SecureTransport condition key specifically evaluates whether the incoming request to an S3 bucket was made using HTTPS (TLS/SSL). When set to "true" in a bucket policy, it mandates that all interactions with the bucket must occur over an encrypted connection, effectively preventing unencrypted HTTP requests. This directly addresses the requirement to ensure that the S3 bucket only allows secure, encrypted data transfer.
Why this answer
The aws:SecureTransport condition checks whether the request was sent using SSL/TLS, effectively enabling HTTPS-only access. Option A is incorrect because aws:CurrentTime is used to allow or deny access based on the time of the request. Option B is incorrect because aws:MultiFactorAuthPresent checks if the requester authenticated with multi-factor authentication.
Option C is incorrect because aws:SourceIp is used to restrict requests based on the source IP address.