Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-secure-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "192.0.2.0/24"
        }
      }
    }
  ]
}

Refer to the exhibit. An administrator has applied the provided bucket policy to 'my-secure-bucket'. What is the effect of this policy on access to the bucket?

⚠ Common exam trap

SAA-C03 often tests the misconception that an Allow statement with an IP condition denies that IP range, when in fact it permits only that range and implicitly denies everything else.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It restricts GetObject access to only those requests originating from the 192.0.2.0/24 CIDR block.

The bucket policy uses a Condition with an IpAddress condition key restricting access to the 192.0.2.0/24 CIDR block, and the Action is s3:GetObject. Therefore only requests originating from that IP range are allowed to retrieve objects; all other requests are denied by default because S3 policies are deny-by-default.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It allows all users to retrieve objects from the bucket if they are using any IP address.

    Why it's wrong here

    The inclusion of the 'IpAddress' condition explicitly limits the scope of the permission. If a user tries to access the bucket from an IP address outside the defined range, the request will be denied. This policy is restrictive rather than permissive for all global traffic.

  • ✗

    It denies access to anyone from the 192.0.2.0/24 range and allows everyone else.

    Why it's wrong here

    The policy uses an 'Allow' effect with a condition that must be met. Therefore, it permits access only for the specified IP range. It does not deny the specified range nor does it grant broad access to the rest of the internet; it effectively creates an IP-based allowlist.

  • ✓

    It restricts GetObject access to only those requests originating from the 192.0.2.0/24 CIDR block.

    Why this is correct

    The 'Condition' block acts as a filter on the 'Allow' statement. By using the 'aws:SourceIp' key, the policy ensures that the 's3:GetObject' action is granted only when the request comes from the specified network, effectively implementing a security perimeter around the S3 bucket's data.

  • ✗

    It grants full administrative access to the bucket for the 192.0.2.0/24 IP range.

    Why it's wrong here

    The policy only grants the 's3:GetObject' action. It does not grant administrative actions like 's3:DeleteBucket', 's3:PutObject', or 's3:PutBucketPolicy'. Administrative access requires a wider set of permissions than what is defined in the action list, so this is not a full administrative policy.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.