Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company wants to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. Which policy element should be used in the S3 bucket policy?

⚠ Common exam trap

Test-takers frequently confuse `aws:SourceVpc` with `aws:SourceVpce`, mistakenly thinking that restricting to a VPC is sufficient, but the question explicitly requires restricting to a specific VPC endpoint, not just any endpoint in the VPC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aws:SourceVpce

To restrict access to an S3 bucket so that only requests originating from a specific VPC endpoint are allowed, the `aws:SourceVpce` condition key must be used in the S3 bucket policy. This key checks the VPC endpoint ID (e.g., `vpce-1a2b3c4d`) from which the request originated, ensuring that only traffic through that specific endpoint is permitted. Using `aws:SourceVpc` would allow any endpoint within the VPC, not a specific one, and `aws:SourceIp` or `aws:Referer` are irrelevant for VPC endpoint-based access control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aws:Referer

    Why it's wrong here

    aws:Referer is a condition key that checks the HTTP Referer header, which web browsers send when linking to a resource. This key is only meaningful for HTTP requests from a browser-based client, such as when using an S3 website endpoint, and it is completely unrelated to identifying a VPC endpoint in a bucket policy. S3 API requests, including those from VPC endpoints, do not carry a Referer header that can be used to enforce network-level access, so it cannot restrict access to a specific VPC endpoint.

  • ✓

    aws:SourceVpce

    Why this is correct

    aws:SourceVpce is the correct condition key because it restricts access to requests that originate from a specific VPC endpoint, identified by its endpoint ID (e.g., vpce-1a2b3c4d). In an S3 bucket policy, you can use this condition key with an explicit Allow statement and the endpoint ID as the value to ensure that only traffic flowing through that particular endpoint can access the bucket. This works for both gateway-gateway and interface VPC endpoints for S3, making it the precise mechanism to limit access to exactly one endpoint.

  • ✗

    aws:SourceVpc

    Why it's wrong here

    aws:SourceVpc restricts access to requests that originate from any resource within a specified VPC, identified by its VPC ID (e.g., vpc-12345678). While this can limit access to a particular VPC, it does not provide the granularity to distinguish between multiple VPC endpoints within that VPC; any endpoint or resource in the VPC would be allowed. Because the requirement is to restrict access to a single specific VPC endpoint, using the VPC ID as the condition allows broader access than intended, making it incorrect.

  • ✗

    aws:SourceIp

    Why it's wrong here

    aws:SourceIp restricts access based on the source IP address of the requesting client. However, when a request comes through an S3 VPC endpoint, the source IP address seen by S3 is typically the private IP address of the instance or the endpoint's network interface, not the endpoint ID itself. This condition key cannot identify the VPC endpoint as the source; it can only match against IP addresses, which are not suitable for allowing or denying a specific VPC endpoint and may also inadvertently block valid traffic or allow unintended traffic depending on IP ranges.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.