SCS-C02 Infrastructure Security Practice Question
A company wants to restrict access to an S3 bucket so that only requests from a specific VPC are allowed. Which policy should be used?
⚠ Common exam trap
Test-takers frequently confuse network-level controls (security groups, NACLs) with service-level controls (bucket policies) and assume that S3 can be protected like an EC2 instance, when in fact S3 only supports bucket policies and IAM policies for access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
S3 bucket policy with aws:SourceVpc condition
S3 bucket policies support the `aws:SourceVpc` condition key, which allows you to restrict access to requests originating from a specific VPC. This works by evaluating the VPC ID from which the request was made, using the source VPC information that AWS automatically includes in requests from VPC endpoints. No other mechanism (security groups, IAM source IP conditions, or network ACLs) can directly enforce VPC-level access control on S3.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security group assigned to the S3 bucket
Why it's wrong here
Security groups are stateful virtual firewalls designed for elastic network interfaces of EC2 instances or other resources like RDS databases—not for managed storage services. An S3 bucket is a global API endpoint, not a resource with an ENI, so you cannot attach a security group to it. Access to S3 is enforced through resource-based policies (bucket policies) and IAM identity policies, not network ACLs or security groups.
- ✗
IAM policy with aws:SourceIp condition
Why it's wrong here
While an IAM policy with an aws:SourceIp condition can restrict the client IP addresses that a user or role may use to call S3 APIs, it does not restrict access to the bucket itself based on VPC origin. Moreover, when traffic traverses a VPC gateway endpoint, the source IP seen by S3 is the private IP of the endpoint, not the original client's public IP, rendering aws:SourceIp unreliable or ineffective. Bucket policies use aws:SourceVpc to restrict by VPC because they operate at the request origin level, not the identity level.
- ✓
S3 bucket policy with aws:SourceVpc condition
Why this is correct
An S3 bucket policy with an aws:SourceVpc condition is the correct way to restrict access to requests originating from a specific VPC. This condition evaluates the VPC ID of the requester, which is available when the request comes through a VPC gateway endpoint (service: s3). It is a resource-based policy, meaning it applies directly to the S3 bucket regardless of which IAM principal makes the request, and is a standard pattern for keeping buckets private to a particular VPC.
- ✗
Network ACL attached to the S3 bucket
Why it's wrong here
Network ACLs (NACLs) are stateless filters that operate at the subnet level in a VPC, controlling inbound and outbound traffic to instances within those subnets. They cannot be attached to an S3 bucket because S3 is not a VPC resource and resides outside the network boundary of your VPC. To restrict S3 access by VPC, you must use a bucket policy with aws:SourceVpc or aws:SourceVpce, or control traffic via VPC endpoint policies, not NACLs.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.