SCS-C02 Infrastructure Security Practice Question
A company has an Amazon S3 bucket that stores sensitive data. The security team wants to ensure that all access to the bucket is made only via HTTPS. Which policy should be used?
⚠ Common exam trap
Candidates often confuse network-level controls (like VPC endpoints or CloudFront) with transport-level encryption enforcement, mistakenly thinking they guarantee HTTPS when they only control the network path or the viewer-to-edge segment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add a bucket policy that denies access when aws:SecureTransport is false.
The condition `aws:SecureTransport` evaluates to `false` when the request is made over HTTP instead of HTTPS. By adding a bucket policy that denies all S3 actions when `aws:SecureTransport` is `false`, the company enforces HTTPS-only access at the policy level, regardless of how the request originates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable CloudFront with HTTPS-only viewer protocol policy.
Why it's wrong here
CloudFront with an HTTPS-only viewer protocol policy can enforce TLS between viewers and the CloudFront distribution, but it does not affect clients that bypass CloudFront and access the S3 bucket's origin endpoint directly. Unless the bucket policy explicitly denies requests from outside CloudFront, direct HTTP requests to the bucket remain valid. Origin Access Control only secures the CloudFront-to-S3 leg, not the viewer-to-origin path. Therefore, this approach cannot guarantee that all access to your S3 data uses HTTPS.
- ✗
Use a VPC endpoint for S3 with a bucket policy that restricts access to the VPC endpoint.
Why it's wrong here
A VPC endpoint for S3 uses AWS's internal network to route traffic, and a bucket policy can restrict access to the endpoint ID, which is useful for keeping the bucket private. However, this configuration only addresses where traffic flows, not how it is transported; a client inside the VPC can still send plaintext HTTP to the endpoint. The aws:sourceVpce condition does not imply or enforce encryption. To require HTTPS, you need a separate condition such as aws:SecureTransport in the bucket policy.
- ✗
Enable 'Block public access' on the bucket.
Why it's wrong here
Enabling 'Block public access' shuts down any public exposure through ACLs, bucket policies, or multi-bucket access points, effectively making the bucket private. It does not alter the security requirements of authenticated requests, so a valid AWS credential can still be used to send an HTTP request over plaintext. This setting has no knowledge of the transport layer and does not evaluate whether the request came in over TLS. It prevents anonymous access but not unencrypted access.
- ✓
Add a bucket policy that denies access when aws:SecureTransport is false.
Why this is correct
A bucket policy that explicitly denies requests when aws:SecureTransport equals false is correct because aws:SecureTransport is a global IAM condition key that is true for HTTPS and false for HTTP. Using a Bool condition with a Deny effect overrides any other allow statement in the policy, so every S3 operation, including from authorized IAM principals, must arrive over TLS. This is the standard way to enforce HTTPS at the S3 API level, and it cannot be bypassed by accessing the bucket directly.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.