SAA-C03 Design Secure Architectures Practice Question
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-secure-bucket/*",
"Condition": {
"IpAddress": {
"aws:SourceIp": "192.0.2.0/24"
}
}
}
]
}Refer to the exhibit. An administrator has applied the provided bucket policy to 'my-secure-bucket'. What is the effect of this policy on access to the bucket?
⚠ Common exam trap
SAA-C03 often tests the misconception that an Allow statement with an IP condition denies that IP range, when in fact it permits only that range and implicitly denies everything else.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It restricts GetObject access to only those requests originating from the 192.0.2.0/24 CIDR block.
The bucket policy uses a Condition with an IpAddress condition key restricting access to the 192.0.2.0/24 CIDR block, and the Action is s3:GetObject. Therefore only requests originating from that IP range are allowed to retrieve objects; all other requests are denied by default because S3 policies are deny-by-default.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It allows all users to retrieve objects from the bucket if they are using any IP address.
Why it's wrong here
The inclusion of the 'IpAddress' condition explicitly limits the scope of the permission. If a user tries to access the bucket from an IP address outside the defined range, the request will be denied. This policy is restrictive rather than permissive for all global traffic.
- ✗
It denies access to anyone from the 192.0.2.0/24 range and allows everyone else.
Why it's wrong here
The policy uses an 'Allow' effect with a condition that must be met. Therefore, it permits access only for the specified IP range. It does not deny the specified range nor does it grant broad access to the rest of the internet; it effectively creates an IP-based allowlist.
- ✓
It restricts GetObject access to only those requests originating from the 192.0.2.0/24 CIDR block.
Why this is correct
The 'Condition' block acts as a filter on the 'Allow' statement. By using the 'aws:SourceIp' key, the policy ensures that the 's3:GetObject' action is granted only when the request comes from the specified network, effectively implementing a security perimeter around the S3 bucket's data.
- ✗
It grants full administrative access to the bucket for the 192.0.2.0/24 IP range.
Why it's wrong here
The policy only grants the 's3:GetObject' action. It does not grant administrative actions like 's3:DeleteBucket', 's3:PutObject', or 's3:PutBucketPolicy'. Administrative access requires a wider set of permissions than what is defined in the action list, so this is not a full administrative policy.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.