SCS-C02 Management and Security Governance Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": "*",
"Resource": "*",
"Condition": {
"Bool": {
"aws:SecureTransport": "false"
}
}
}
]
}A security engineer applies the above bucket policy to an S3 bucket. What is the effect of this policy?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
All requests to the bucket must be made over HTTPS.
The bucket policy includes a statement that denies all actions (s3:*) when the request does not use HTTPS (aws:SecureTransport is false). This effectively requires all requests to the bucket to be made over HTTPS. Therefore, option B is correct. Option A is incorrect because the policy does not deny all requests; it only denies non-HTTPS requests. Option C is incorrect because the condition does have an effect. Option D is incorrect because HTTP requests are denied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All requests to the bucket are denied regardless of protocol.
Why it's wrong here
The Deny in this policy is narrow rather than absolute—it applies only when the condition aws:SecureTransport: "false" is satisfied. An HTTPS request sets SecureTransport to "true", so the Deny statement is not triggered and the request is allowed. Consequently, HTTPS requests are permitted while HTTP requests are denied; this is not a blanket denial of all requests regardless of protocol.
- ✓
All requests to the bucket must be made over HTTPS.
Why this is correct
This policy uses an explicit Deny with a Bool condition that matches when aws:SecureTransport is false, meaning "if the request did not arrive over TLS/HTTPS, deny it." Since S3 evaluates this explicit Deny before any Allow, even a statement allowing s3:GetObject cannot override it for HTTP requests. The net effect is that every successful request to the bucket must be made over HTTPS.
- ✗
The policy has no effect because it uses a condition.
Why it's wrong here
S3 bucket policies are declarative JSON, and the Condition block is a standard element used to make an Allow or Deny context-dependent—it does not make the policy inert. In this policy, the Bool condition on aws:SecureTransport: "false" is evaluated for every request, and when it matches, the Deny statement takes effect. Therefore the policy absolutely has an effect by blocking non-HTTPS traffic; claiming it has no effect misreads the purpose of Condition.
- ✗
All requests to the bucket must be made over HTTP.
Why it's wrong here
This option reverses the policy's actual intent. The Deny effect fires only when aws:SecureTransport equals "false", which is precisely what is true for plain HTTP requests. Thus HTTP is explicitly prohibited, not required, and only requests sent over TLS/HTTPS have SecureTransport set to "true" and are allowed to pass.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.