SCS-C02 Infrastructure Security Practice Question
A company wants to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. Which policy element should be used in the S3 bucket policy?
⚠ Common exam trap
Test-takers frequently confuse `aws:SourceVpc` with `aws:SourceVpce`, mistakenly thinking that restricting to a VPC is sufficient, but the question explicitly requires restricting to a specific VPC endpoint, not just any endpoint in the VPC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aws:SourceVpce
To restrict access to an S3 bucket so that only requests originating from a specific VPC endpoint are allowed, the `aws:SourceVpce` condition key must be used in the S3 bucket policy. This key checks the VPC endpoint ID (e.g., `vpce-1a2b3c4d`) from which the request originated, ensuring that only traffic through that specific endpoint is permitted. Using `aws:SourceVpc` would allow any endpoint within the VPC, not a specific one, and `aws:SourceIp` or `aws:Referer` are irrelevant for VPC endpoint-based access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aws:Referer
Why it's wrong here
aws:Referer is a condition key that checks the HTTP Referer header, which web browsers send when linking to a resource. This key is only meaningful for HTTP requests from a browser-based client, such as when using an S3 website endpoint, and it is completely unrelated to identifying a VPC endpoint in a bucket policy. S3 API requests, including those from VPC endpoints, do not carry a Referer header that can be used to enforce network-level access, so it cannot restrict access to a specific VPC endpoint.
- ✓
aws:SourceVpce
Why this is correct
aws:SourceVpce is the correct condition key because it restricts access to requests that originate from a specific VPC endpoint, identified by its endpoint ID (e.g., vpce-1a2b3c4d). In an S3 bucket policy, you can use this condition key with an explicit Allow statement and the endpoint ID as the value to ensure that only traffic flowing through that particular endpoint can access the bucket. This works for both gateway-gateway and interface VPC endpoints for S3, making it the precise mechanism to limit access to exactly one endpoint.
- ✗
aws:SourceVpc
Why it's wrong here
aws:SourceVpc restricts access to requests that originate from any resource within a specified VPC, identified by its VPC ID (e.g., vpc-12345678). While this can limit access to a particular VPC, it does not provide the granularity to distinguish between multiple VPC endpoints within that VPC; any endpoint or resource in the VPC would be allowed. Because the requirement is to restrict access to a single specific VPC endpoint, using the VPC ID as the condition allows broader access than intended, making it incorrect.
- ✗
aws:SourceIp
Why it's wrong here
aws:SourceIp restricts access based on the source IP address of the requesting client. However, when a request comes through an S3 VPC endpoint, the source IP address seen by S3 is typically the private IP address of the instance or the endpoint's network interface, not the endpoint ID itself. This condition key cannot identify the VPC endpoint as the source; it can only match against IP addresses, which are not suitable for allowing or denying a specific VPC endpoint and may also inadvertently block valid traffic or allow unintended traffic depending on IP ranges.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.