SAP-C02 Design for New Solutions Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::example-bucket/*",
"Condition": {
"IpAddress": {
"aws:SourceIp": "10.0.0.0/8"
}
}
},
{
"Effect": "Deny",
"Action": "s3:*",
"Resource": "arn:aws:s3:::example-bucket/*",
"Condition": {
"Bool": {
"aws:SecureTransport": "false"
}
}
}
]
}A solutions architect is reviewing the above IAM policy attached to an S3 bucket. A user from IP address 10.0.1.5 makes a request over HTTP (not HTTPS). Will the user be able to download an object?
⚠ Common exam trap
SAP-C02 often tests the misconception that if an IP address is allowed, access is granted regardless of other conditions, but the trap is forgetting that all conditions in a statement must be satisfied for the Allow to take effect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No, because the request is not using HTTPS.
The IAM policy includes a condition that requires requests to use HTTPS (aws:SecureTransport = true). Since the user's request is over HTTP, the condition fails, and the Allow statement does not apply. Therefore, the request is denied by default, and the user cannot download the object.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
No, because the IP address is not in the allowed range.
Why it's wrong here
10.0.1.5 does fall within the allowed range, so the IP condition passes; the request fails because it uses HTTP, triggering the SecureTransport Deny. Range-based rejection is tempting since CIDR matching is a common access control, but here the transport condition is decisive.
- ✗
Yes, because the IP address is allowed.
Why it's wrong here
The IP condition is satisfied, but the policy's Deny on aws:SecureTransport false blocks any request over HTTP, and explicit Deny overrides Allow. IP allowlisting is tempting because it governs network origin, and would grant access if the request arrived over HTTPS.
- ✓
No, because the request is not using HTTPS.
Why this is correct
The policy's explicit Deny for `aws:SecureTransport: false` overrides any Allow, so the HTTP request from 10.0.1.5 is blocked regardless of source IP. AWS evaluates Deny first, making the insecure transport condition the decisive constraint that prevents the object download.
- ✗
Yes, because the Allow statement is evaluated first.
Why it's wrong here
IAM evaluates all statements together; an explicit Deny always overrides any Allow, regardless of order. Allow-first evaluation is tempting because it sounds like a precedence rule, but the actual mechanism is deny-wins, so the HTTP request is refused despite the matching Allow.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.