Courseiva

SCS-C02 Management and Security Governance Practice Question

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Action": "*",
      "Resource": "*",
      "Condition": {
        "Bool": {
          "aws:SecureTransport": "false"
        }
      }
    }
  ]
}

A security engineer applies the above bucket policy to an S3 bucket. What is the effect of this policy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

All requests to the bucket must be made over HTTPS.

The bucket policy includes a statement that denies all actions (s3:*) when the request does not use HTTPS (aws:SecureTransport is false). This effectively requires all requests to the bucket to be made over HTTPS. Therefore, option B is correct. Option A is incorrect because the policy does not deny all requests; it only denies non-HTTPS requests. Option C is incorrect because the condition does have an effect. Option D is incorrect because HTTP requests are denied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All requests to the bucket are denied regardless of protocol.

    Why it's wrong here

    The Deny in this policy is narrow rather than absolute—it applies only when the condition aws:SecureTransport: "false" is satisfied. An HTTPS request sets SecureTransport to "true", so the Deny statement is not triggered and the request is allowed. Consequently, HTTPS requests are permitted while HTTP requests are denied; this is not a blanket denial of all requests regardless of protocol.

  • ✓

    All requests to the bucket must be made over HTTPS.

    Why this is correct

    This policy uses an explicit Deny with a Bool condition that matches when aws:SecureTransport is false, meaning "if the request did not arrive over TLS/HTTPS, deny it." Since S3 evaluates this explicit Deny before any Allow, even a statement allowing s3:GetObject cannot override it for HTTP requests. The net effect is that every successful request to the bucket must be made over HTTPS.

  • ✗

    The policy has no effect because it uses a condition.

    Why it's wrong here

    S3 bucket policies are declarative JSON, and the Condition block is a standard element used to make an Allow or Deny context-dependent—it does not make the policy inert. In this policy, the Bool condition on aws:SecureTransport: "false" is evaluated for every request, and when it matches, the Deny statement takes effect. Therefore the policy absolutely has an effect by blocking non-HTTPS traffic; claiming it has no effect misreads the purpose of Condition.

  • ✗

    All requests to the bucket must be made over HTTP.

    Why it's wrong here

    This option reverses the policy's actual intent. The Deny effect fires only when aws:SecureTransport equals "false", which is precisely what is true for plain HTTP requests. Thus HTTP is explicitly prohibited, not required, and only requests sent over TLS/HTTPS have SecureTransport set to "true" and are allowed to pass.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.