SCS-C02 Infrastructure Security Practice Question
A company has an Amazon S3 bucket that stores sensitive data. The security team needs to ensure that all access to the bucket is encrypted in transit. Which condition should be added to the bucket policy?
⚠ Common exam trap
A common mix-up: candidates confuse encryption in transit (HTTPS/TLS) with encryption at rest (server-side encryption), leading them to select `s3:x-amz-server-side-encryption` instead of `aws:SecureTransport`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aws:SecureTransport
The `aws:SecureTransport` condition key in an S3 bucket policy enforces that all requests to the bucket must be made over HTTPS (TLS). When set to `false`, any HTTP request is denied, ensuring data is encrypted in transit. This directly addresses the security team's requirement to encrypt all access to the bucket during transmission.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
aws:SecureTransport
Why this is correct
The aws:SecureTransport condition key is a global IAM condition that evaluates to true only when the request to S3 was made over HTTPS/TLS. By including it in a bucket policy with a Deny effect, you can reject any HTTP request, thereby enforcing encryption in transit for all S3 API operations. This condition directly addresses the requirement that sensitive data not be transmitted in plaintext.
- ✗
aws:SourceIp
Why it's wrong here
The aws:SourceIp condition key evaluates the originating IP address of the requester, not the transport protocol. It is commonly used to restrict access to certain networks, but it cannot detect whether a request arrives over HTTP or HTTPS. Thus, it provides no enforcement of encryption in transit and would allow cleartext traffic from an allowed IP.
- ✗
s3:x-amz-server-side-encryption
Why it's wrong here
The s3:x-amz-server-side-encryption condition key checks for the presence of the x-amz-server-side-encryption request header, which requests encryption at rest (e.g., SSE-S3 or SSE-KMS). It does not inspect the transport channel, so a request with this header can still be sent over insecure HTTP. This condition controls how data is stored, not how it is transmitted.
- ✗
aws:UserAgent
Why it's wrong here
The aws:UserAgent condition key matches the User-Agent header sent by the client application, which is often used for monitoring or access logging. It is trivially spoofable and carries no information about TLS usage or the security of the connection. Using it to enforce encryption would be ineffective because a user can simply modify the header while still sending plaintext HTTP.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.