SCS-C02 Identity and Access Management Practice Question
A security engineer is configuring a VPC endpoint for Amazon S3 and wants to ensure that only traffic from specific IAM roles can access the S3 bucket through the endpoint. Which policy element should the engineer use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aws:PrincipalArn
Aws:PrincipalArn. This condition key allows you to specify the ARN of an IAM role (or user) to control access to the S3 bucket through the VPC endpoint. Option A (aws:SourceVpc) restricts traffic to a specific VPC, not an IAM role. Option C (aws:username) is used for IAM users, not roles. Option D (aws:SourceVpce) restricts traffic to a specific VPC endpoint, not a role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aws:SourceVpc
Why it's wrong here
The aws:SourceVpc condition key matches the ID of the VPC from which the request originates, and it is only available when the request comes through a VPC endpoint. Like aws:SourceVpce, it is a network topology condition that does not carry any information about the IAM principal. Hence, it cannot be used to control access based on a specific IAM role; it merely identifies the VPC, which may contain many roles and workloads.
- ✓
aws:PrincipalArn
Why this is correct
The aws:PrincipalArn condition key matches the full ARN of the IAM principal (user or role) that is making the request. For a VPC endpoint policy controlling access to Amazon S3, you can specify a role ARN as the value, ensuring only requests signed with that role's credentials are allowed through the endpoint. This is the correct way to restrict access to a specific IAM role because it directly inspects the principal identity rather than the network source.
- ✗
aws:username
Why it's wrong here
The aws:username condition key is only populated for requests made by an IAM user; it is absent for requests made by an IAM role or via temporary security credentials from an assumed role. Since the requirement is to allow a specific IAM role, aws:username cannot be used because it does not provide the role's identifier. In fact, for role-signed requests, aws:username is null, so the condition would never match.
- ✗
aws:SourceVpce
Why it's wrong here
The aws:SourceVpce condition key restricts access based on the ID of the VPC endpoint (e.g., vpce-12345678) that received the request. It is a network-origin condition, not an identity condition, so it cannot indicate which IAM role is allowed. While it can be useful to limit traffic to a particular endpoint, it is completely unrelated to the principal's ARN and therefore does not satisfy the requirement to restrict access by role.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.