SCS-C02 Data Protection Practice Question
A company stores sensitive data in an Amazon S3 bucket. They want to ensure that data is encrypted in transit when accessed from the internet. Which policy should they attach to the bucket?
⚠ Common exam trap
Test-takers frequently choose an Allow policy (like Option B) thinking it will permit only encrypted traffic, but they forget that an Allow with a condition does not block unencrypted requests—only a Deny can explicitly block them, and the condition must be inverted (e.g., 'false' to block HTTP).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"Bool": {"aws:SecureTransport": "false"}}}
It uses a Deny effect with the aws:SecureTransport condition set to 'false', which explicitly blocks any request that does not use HTTPS/TLS. This ensures that all S3 operations (s3:*) on the bucket objects require encryption in transit, as any HTTP request will be denied. The Deny effect overrides any Allow, making this a robust policy to enforce encrypted access from the internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
{"Effect": "Deny", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"StringNotEquals": {"aws:SourceVpc": "vpc-12345"}}}
Why it's wrong here
This policy denies any s3:GetObject request that does not originate from the specified VPC endpoint (vpc-12345), using the aws:SourceVpc condition. While it can restrict access to a particular network, it does nothing to enforce encryption in transit; an HTTP request from within the VPC would still be allowed. The missing piece is the aws:SecureTransport check, so this statement fails to meet the requirement for securing data in transit.
- ✗
{"Effect": "Allow", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"Bool": {"aws:SecureTransport": "false"}}}
Why it's wrong here
An Allow effect combined with the condition Bool aws:SecureTransport: false explicitly permits requests made over plain HTTP, which is the opposite of the security requirement. It effectively grants public access to s3:GetObject without any transport encryption, leaving the data vulnerable to interception. This policy not only fails to enforce HTTPS but actively encourages insecure access, making it doubly unsuitable.
- ✓
{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"Bool": {"aws:SecureTransport": "false"}}}
Why this is correct
This is the correct policy because it denies all S3 actions (s3:*) when the request is not using secure transport, as indicated by aws:SecureTransport being false. By using Deny on the entire action set and the Bool condition, it ensures that any request over HTTP is rejected, while HTTPS requests remain unaffected. This is the standard AWS recommended pattern for enforcing encryption in transit on an S3 bucket.
- ✗
{"Effect": "Deny", "Principal": "*", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::bucket/*", "Condition": {"IpAddress": {"aws:SourceIp": "0.0.0.0/0"}}}
Why it's wrong here
This policy attempts to deny s3:GetObject by setting aws:SourceIp to 0.0.0.0/0, which is the CIDR for all IP addresses, so it would effectively block every request to the object. However, it has no relation to transport security; it's an IP-based restriction that would prevent all access regardless of whether HTTPS is used. The correct approach should use aws:SecureTransport to gate on encryption, not IP addresses.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.