SCS-C02 Infrastructure Security Practice Question
A company wants to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. Which S3 bucket policy condition key should be used?
⚠ Common exam trap
Many exam-takers confuse `aws:SourceVpc` (which restricts by VPC ID) with `aws:SourceVpce` (which restricts by VPC endpoint ID), leading them to select the wrong condition key when the requirement is specifically to allow only traffic from a particular VPC endpoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aws:SourceVpce
To restrict access to an S3 bucket so that only requests originating from a specific VPC endpoint are allowed, you must use the `aws:SourceVpce` condition key in the S3 bucket policy. This key evaluates the VPC endpoint ID (e.g., `vpce-1a2b3c4d`) of the request, ensuring that only traffic routed through that specific endpoint is granted access. The `aws:SourceVpc` key is used to restrict access based on the VPC ID, not the endpoint ID, and `aws:SourceIp` and `aws:VpcSourceIp` are not valid condition keys for VPC endpoint-based restrictions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aws:VpcSourceIp
Why it's wrong here
aws:VpcSourceIp is not a recognized IAM condition key in any AWS service, including S3. AWS global condition keys use aws:SourceIp for client IP addresses, and VPC-specific keys are aws:SourceVpc or aws:SourceVpce. Since this key does not exist, it cannot evaluate to true in a policy, so it would fail to allow any access.
- ✗
aws:SourceVpc
Why it's wrong here
aws:SourceVpc restricts access to requests that originate from any interface or flow within a specified VPC, matching the VPC ID in the condition. This is broader than the requirement because it includes traffic that reaches S3 through NAT, VPN, or Direct Connect from resources in that VPC, not just through a specific VPC endpoint. To limit access to a single VPC endpoint, you need a condition key that identifies that endpoint rather than the entire VPC.
- ✓
aws:SourceVpce
Why this is correct
The aws:SourceVpce condition key is explicitly designed for VPC endpoints and lets you match the ID of the VPC endpoint through which the request was made, such as vpce-12345678. By placing a StringEquals condition in the bucket policy, you can allow access only when the request arrives via that exact endpoint. This satisfies the requirement to restrict access to a specific VPC endpoint, while all other traffic is implicitly denied.
- ✗
aws:SourceIp
Why it's wrong here
aws:SourceIp restricts based on the source IP address of the requester, which is often the public IP address for internet traffic or the private IP address for traffic within a VPC. For requests sent through a VPC endpoint, the S3 service sees the source IP as a private IP from the VPC, but that does not indicate which endpoint was used. Moreover, the source IP can change or be shared by multiple resources, so it cannot identify a unique VPC endpoint for the required access restriction.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.