Courseiva
Data Protection →mediumMultiple Choice

SCS-C02 Data Protection Practice Question

A company wants to protect sensitive data stored in Amazon S3 by enforcing encryption in transit. Which policy should be used to deny requests that do not use HTTPS?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

{"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*", "Condition": {"Bool": {"aws:SecureTransport": "false"}}}

It uses the aws:SecureTransport condition set to 'false' to deny requests that are not using HTTPS. Option A is incorrect because it denies requests when SecureTransport is 'true', meaning it would block legitimate HTTPS traffic. Option C is incorrect because it checks for the presence of the s3:x-amz-server-side-encryption header, which relates to encryption at rest, not encryption in transit. Option D is incorrect because it denies all requests unconditionally, which would block all traffic, including HTTPS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    {"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*", "Condition": {"Bool": {"aws:SecureTransport": "true"}}}

    Why it's wrong here

    This policy denies all S3 actions when the aws:SecureTransport condition key evaluates to true, which is the exact opposite of the intended protection. Since aws:SecureTransport is true for HTTPS requests, this deny statement blocks legitimate encrypted traffic and effectively leaves only insecure HTTP requests unblocked. It thus fails to protect data in transit and actively prevents secure access to the bucket.

  • ✓

    {"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*", "Condition": {"Bool": {"aws:SecureTransport": "false"}}}

    Why this is correct

    This policy correctly denies S3 actions when aws:SecureTransport is false, meaning it blocks all HTTP requests that do not use TLS. The aws:SecureTransport key is true only for requests made over HTTPS, so this conditional deny rejects any insecure request while allowing encrypted traffic. This is the AWS-recommended bucket policy pattern for enforcing encryption in transit and satisfies the requirement.

  • ✗

    {"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*", "Condition": {"Null": {"s3:x-amz-server-side-encryption": "true"}}}

    Why it's wrong here

    This policy attempts to enforce encryption at rest rather than in transit by denying requests when the s3:x-amz-server-side-encryption header is absent (Null true). The condition key checks for the presence of a server-side encryption header, not for whether the request is sent over HTTPS, so it does not address data-in-transit protection. Even an HTTP request could include that header, so insecure transport would not be blocked.

  • ✗

    {"Effect": "Deny", "Principal": "*", "Action": "s3:*", "Resource": "*"}

    Why it's wrong here

    This bucket policy denies all S3 actions without any condition key, which makes it far too restrictive for the stated requirement. It would block both HTTPS and HTTP requests, rendering the bucket completely inaccessible to all principals. Such a policy prevents all legitimate use and does not selectively target insecure transmission, so it fails the need to enforce TLS while preserving secure access.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.