Courseiva
Design for New Solutions →hardMultiple Choice

SAP-C02 Design for New Solutions Practice Question

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "10.0.0.0/8"
        }
      }
    },
    {
      "Effect": "Deny",
      "Action": "s3:*",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "Bool": {
          "aws:SecureTransport": "false"
        }
      }
    }
  ]
}

A solutions architect is reviewing the above IAM policy attached to an S3 bucket. A user from IP address 10.0.1.5 makes a request over HTTP (not HTTPS). Will the user be able to download an object?

⚠ Common exam trap

SAP-C02 often tests the misconception that if an IP address is allowed, access is granted regardless of other conditions, but the trap is forgetting that all conditions in a statement must be satisfied for the Allow to take effect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No, because the request is not using HTTPS.

The IAM policy includes a condition that requires requests to use HTTPS (aws:SecureTransport = true). Since the user's request is over HTTP, the condition fails, and the Allow statement does not apply. Therefore, the request is denied by default, and the user cannot download the object.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    No, because the IP address is not in the allowed range.

    Why it's wrong here

    10.0.1.5 does fall within the allowed range, so the IP condition passes; the request fails because it uses HTTP, triggering the SecureTransport Deny. Range-based rejection is tempting since CIDR matching is a common access control, but here the transport condition is decisive.

  • ✗

    Yes, because the IP address is allowed.

    Why it's wrong here

    The IP condition is satisfied, but the policy's Deny on aws:SecureTransport false blocks any request over HTTP, and explicit Deny overrides Allow. IP allowlisting is tempting because it governs network origin, and would grant access if the request arrived over HTTPS.

  • ✓

    No, because the request is not using HTTPS.

    Why this is correct

    The policy's explicit Deny for `aws:SecureTransport: false` overrides any Allow, so the HTTP request from 10.0.1.5 is blocked regardless of source IP. AWS evaluates Deny first, making the insecure transport condition the decisive constraint that prevents the object download.

  • ✗

    Yes, because the Allow statement is evaluated first.

    Why it's wrong here

    IAM evaluates all statements together; an explicit Deny always overrides any Allow, regardless of order. Allow-first evaluation is tempting because it sounds like a precedence rule, but the actual mechanism is deny-wins, so the HTTP request is refused despite the matching Allow.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.