Courseiva

SCS-C02 Identity and Access Management Practice Question

A company has an S3 bucket that contains sensitive data. The security team wants to ensure that all access to the bucket is encrypted in transit. What is the most effective way to enforce this?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a bucket policy that denies access if the request does not use HTTPS (aws:SecureTransport condition).

A bucket policy with the aws:SecureTransport condition denies any request that does not use HTTPS, enforcing encryption in transit. Option A is incorrect because SSE-S3 only encrypts data at rest, not during transmission. Option B is incorrect because CloudTrail logs access but does not enforce encryption. Option D is incorrect because an IAM policy can deny non-HTTPS requests, but enforcing this at the bucket policy level is more direct and applies to all principals accessing the bucket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable default encryption on the S3 bucket using SSE-S3.

    Why it's wrong here

    Default encryption with SSE-S3 encrypts objects at rest using Amazon-managed keys, so it protects data stored in S3. However, it does nothing to secure the transport layer: a client could still upload or download objects over plain HTTP if the bucket policy allows it. Encryption in transit must be enforced separately using the aws:SecureTransport condition in a policy. Therefore, this option does not prevent non-HTTPS requests.

  • ✗

    Enable AWS CloudTrail to log all S3 access and alert on non-HTTPS requests.

    Why it's wrong here

    CloudTrail is a logging service that records API activity, including S3 requests, and can trigger alerts via CloudWatch Events when non-HTTPS requests occur. However, logging and alerting are detective controls, not preventative controls—they cannot deny or block a request at the time it is made. To enforce HTTPS, you need a resource-based or identity-based policy with the aws:SecureTransport condition, because CloudTrail only captures evidence of the problem after the fact.

  • ✓

    Add a bucket policy that denies access if the request does not use HTTPS (aws:SecureTransport condition).

    Why this is correct

    Adding a bucket policy with a Deny effect and the condition `aws:SecureTransport: false` will reject any request that is not sent over SSL/TLS. This is the most direct and comprehensive way to enforce HTTPS on S3 because the bucket policy is evaluated for every request to the bucket, regardless of which IAM principal, account, or anonymous user makes it. Using a resource-based policy at the bucket level also aligns with AWS best practices for S3 security and is the recommended mechanism to mandate encrypted connections.

  • ✗

    Create an IAM policy that denies S3 actions without the condition aws:SecureTransport.

    Why it's wrong here

    An IAM policy with the same `aws:SecureTransport` condition could deny S3 actions for principals it is attached to, but IAM policies are identity-based and therefore only affect the specific users, groups, or roles that have the policy. This leaves gaps: it would not apply to anonymous (unauthenticated) requests, requests from other AWS accounts, or service principals unless every possible principal is covered. A bucket policy is simpler and more reliable because it attaches the condition directly to the S3 resource, making it applicable to all callers.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.