DOP-C02 Security and Compliance Practice Question
A DevOps engineer needs to ensure that an S3 bucket policy enforces encryption in transit for all access. Which policy statement should be added?
⚠ Common exam trap
DOP-C02 often tests whether candidates confuse the boolean logic of aws:SecureTransport, leading them to select an Allow statement or a Deny with the wrong boolean value, instead of the correct Deny with false.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
{"Effect":"Deny","Condition":{"Bool":{"aws:SecureTransport":"false"}}}
To enforce encryption in transit, the S3 bucket policy must deny requests that are not using SSL/TLS. The condition key aws:SecureTransport is a boolean that is true when the request uses HTTPS and false when it uses HTTP. Therefore, a Deny statement with a condition that aws:SecureTransport is false blocks all unencrypted (HTTP) access, effectively enforcing encryption in transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
{"Effect":"Deny","Condition":{"StringEquals":{"aws:SecureTransport":"true"}}}
Why it's wrong here
The condition key aws:SecureTransport is a boolean value, so using StringEquals is invalid; condition operators must match the key type. Even if StringEquals could evaluate it, Deny on true would block HTTPS requests and allow HTTP, inverting the security requirement. The correct operator for boolean keys is Bool, and the value to deny is false.
- ✗
{"Effect":"Allow","Condition":{"Bool":{"aws:SecureTransport":"false"}}}
Why it's wrong here
An Allow effect with SecureTransport false explicitly concedes access via HTTP, which is exactly what the policy is supposed to prevent. It also does not prevent HTTPS access, but that is not the problem; the problem is it grants insecure access. To enforce HTTPS, you must deny insecure requests, not allow them, and use false as the condition value.
- ✗
{"Effect":"Allow","Condition":{"Bool":{"aws:SecureTransport":"true"}}}
Why it's wrong here
This statement only allows HTTPS but does not explicitly deny HTTP. If another IAM policy or bucket policy grants access, an HTTP request could still succeed because an explicit deny is required to override other allows. The industry standard is to place an explicit Deny on SecureTransport false, making the Allow-on-true pattern insufficient and unreliable.
- ✓
{"Effect":"Deny","Condition":{"Bool":{"aws:SecureTransport":"false"}}}
Why this is correct
This is the correct pattern: it explicitly denies any request where aws:SecureTransport equals false, meaning only HTTPS connections are permitted. An explicit deny overrides all other allow outcomes, so this robustly enforces TLS regardless of any other policies. The condition uses Bool, which is proper for boolean keys like aws:SecureTransport.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.