Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A DevOps engineer needs to ensure that an S3 bucket policy enforces encryption in transit for all access. Which policy statement should be added?

⚠ Common exam trap

DOP-C02 often tests whether candidates confuse the boolean logic of aws:SecureTransport, leading them to select an Allow statement or a Deny with the wrong boolean value, instead of the correct Deny with false.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

{"Effect":"Deny","Condition":{"Bool":{"aws:SecureTransport":"false"}}}

To enforce encryption in transit, the S3 bucket policy must deny requests that are not using SSL/TLS. The condition key aws:SecureTransport is a boolean that is true when the request uses HTTPS and false when it uses HTTP. Therefore, a Deny statement with a condition that aws:SecureTransport is false blocks all unencrypted (HTTP) access, effectively enforcing encryption in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    {"Effect":"Deny","Condition":{"StringEquals":{"aws:SecureTransport":"true"}}}

    Why it's wrong here

    The condition key aws:SecureTransport is a boolean value, so using StringEquals is invalid; condition operators must match the key type. Even if StringEquals could evaluate it, Deny on true would block HTTPS requests and allow HTTP, inverting the security requirement. The correct operator for boolean keys is Bool, and the value to deny is false.

  • ✗

    {"Effect":"Allow","Condition":{"Bool":{"aws:SecureTransport":"false"}}}

    Why it's wrong here

    An Allow effect with SecureTransport false explicitly concedes access via HTTP, which is exactly what the policy is supposed to prevent. It also does not prevent HTTPS access, but that is not the problem; the problem is it grants insecure access. To enforce HTTPS, you must deny insecure requests, not allow them, and use false as the condition value.

  • ✗

    {"Effect":"Allow","Condition":{"Bool":{"aws:SecureTransport":"true"}}}

    Why it's wrong here

    This statement only allows HTTPS but does not explicitly deny HTTP. If another IAM policy or bucket policy grants access, an HTTP request could still succeed because an explicit deny is required to override other allows. The industry standard is to place an explicit Deny on SecureTransport false, making the Allow-on-true pattern insufficient and unreliable.

  • ✓

    {"Effect":"Deny","Condition":{"Bool":{"aws:SecureTransport":"false"}}}

    Why this is correct

    This is the correct pattern: it explicitly denies any request where aws:SecureTransport equals false, meaning only HTTPS connections are permitted. An explicit deny overrides all other allow outcomes, so this robustly enforces TLS regardless of any other policies. The condition uses Bool, which is proper for boolean keys like aws:SecureTransport.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.