Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC are allowed. Which policy should be used?

⚠ Common exam trap

Test-takers frequently confuse network-level controls (security groups, NACLs) with service-level controls (bucket policies) and assume that S3 can be protected like an EC2 instance, when in fact S3 only supports bucket policies and IAM policies for access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

S3 bucket policy with aws:SourceVpc condition

S3 bucket policies support the `aws:SourceVpc` condition key, which allows you to restrict access to requests originating from a specific VPC. This works by evaluating the VPC ID from which the request was made, using the source VPC information that AWS automatically includes in requests from VPC endpoints. No other mechanism (security groups, IAM source IP conditions, or network ACLs) can directly enforce VPC-level access control on S3.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security group assigned to the S3 bucket

    Why it's wrong here

    Security groups are stateful virtual firewalls designed for elastic network interfaces of EC2 instances or other resources like RDS databases—not for managed storage services. An S3 bucket is a global API endpoint, not a resource with an ENI, so you cannot attach a security group to it. Access to S3 is enforced through resource-based policies (bucket policies) and IAM identity policies, not network ACLs or security groups.

  • ✗

    IAM policy with aws:SourceIp condition

    Why it's wrong here

    While an IAM policy with an aws:SourceIp condition can restrict the client IP addresses that a user or role may use to call S3 APIs, it does not restrict access to the bucket itself based on VPC origin. Moreover, when traffic traverses a VPC gateway endpoint, the source IP seen by S3 is the private IP of the endpoint, not the original client's public IP, rendering aws:SourceIp unreliable or ineffective. Bucket policies use aws:SourceVpc to restrict by VPC because they operate at the request origin level, not the identity level.

  • ✓

    S3 bucket policy with aws:SourceVpc condition

    Why this is correct

    An S3 bucket policy with an aws:SourceVpc condition is the correct way to restrict access to requests originating from a specific VPC. This condition evaluates the VPC ID of the requester, which is available when the request comes through a VPC gateway endpoint (service: s3). It is a resource-based policy, meaning it applies directly to the S3 bucket regardless of which IAM principal makes the request, and is a standard pattern for keeping buckets private to a particular VPC.

  • ✗

    Network ACL attached to the S3 bucket

    Why it's wrong here

    Network ACLs (NACLs) are stateless filters that operate at the subnet level in a VPC, controlling inbound and outbound traffic to instances within those subnets. They cannot be attached to an S3 bucket because S3 is not a VPC resource and resides outside the network boundary of your VPC. To restrict S3 access by VPC, you must use a bucket policy with aws:SourceVpc or aws:SourceVpce, or control traffic via VPC endpoint policies, not NACLs.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.