Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company has an Amazon S3 bucket that stores sensitive data. The security team wants to ensure that all access to the bucket is made only via HTTPS. Which policy should be used?

⚠ Common exam trap

Candidates often confuse network-level controls (like VPC endpoints or CloudFront) with transport-level encryption enforcement, mistakenly thinking they guarantee HTTPS when they only control the network path or the viewer-to-edge segment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a bucket policy that denies access when aws:SecureTransport is false.

The condition `aws:SecureTransport` evaluates to `false` when the request is made over HTTP instead of HTTPS. By adding a bucket policy that denies all S3 actions when `aws:SecureTransport` is `false`, the company enforces HTTPS-only access at the policy level, regardless of how the request originates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable CloudFront with HTTPS-only viewer protocol policy.

    Why it's wrong here

    CloudFront with an HTTPS-only viewer protocol policy can enforce TLS between viewers and the CloudFront distribution, but it does not affect clients that bypass CloudFront and access the S3 bucket's origin endpoint directly. Unless the bucket policy explicitly denies requests from outside CloudFront, direct HTTP requests to the bucket remain valid. Origin Access Control only secures the CloudFront-to-S3 leg, not the viewer-to-origin path. Therefore, this approach cannot guarantee that all access to your S3 data uses HTTPS.

  • ✗

    Use a VPC endpoint for S3 with a bucket policy that restricts access to the VPC endpoint.

    Why it's wrong here

    A VPC endpoint for S3 uses AWS's internal network to route traffic, and a bucket policy can restrict access to the endpoint ID, which is useful for keeping the bucket private. However, this configuration only addresses where traffic flows, not how it is transported; a client inside the VPC can still send plaintext HTTP to the endpoint. The aws:sourceVpce condition does not imply or enforce encryption. To require HTTPS, you need a separate condition such as aws:SecureTransport in the bucket policy.

  • ✗

    Enable 'Block public access' on the bucket.

    Why it's wrong here

    Enabling 'Block public access' shuts down any public exposure through ACLs, bucket policies, or multi-bucket access points, effectively making the bucket private. It does not alter the security requirements of authenticated requests, so a valid AWS credential can still be used to send an HTTP request over plaintext. This setting has no knowledge of the transport layer and does not evaluate whether the request came in over TLS. It prevents anonymous access but not unencrypted access.

  • ✓

    Add a bucket policy that denies access when aws:SecureTransport is false.

    Why this is correct

    A bucket policy that explicitly denies requests when aws:SecureTransport equals false is correct because aws:SecureTransport is a global IAM condition key that is true for HTTPS and false for HTTP. Using a Bool condition with a Deny effect overrides any other allow statement in the policy, so every S3 operation, including from authorized IAM principals, must arrive over TLS. This is the standard way to enforce HTTPS at the S3 API level, and it cannot be bypassed by accessing the bucket directly.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.