Courseiva

SCS-C02 Identity and Access Management Practice Question

A security engineer is configuring a VPC endpoint for Amazon S3 and wants to ensure that only traffic from specific IAM roles can access the S3 bucket through the endpoint. Which policy element should the engineer use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aws:PrincipalArn

Aws:PrincipalArn. This condition key allows you to specify the ARN of an IAM role (or user) to control access to the S3 bucket through the VPC endpoint. Option A (aws:SourceVpc) restricts traffic to a specific VPC, not an IAM role. Option C (aws:username) is used for IAM users, not roles. Option D (aws:SourceVpce) restricts traffic to a specific VPC endpoint, not a role.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aws:SourceVpc

    Why it's wrong here

    The aws:SourceVpc condition key matches the ID of the VPC from which the request originates, and it is only available when the request comes through a VPC endpoint. Like aws:SourceVpce, it is a network topology condition that does not carry any information about the IAM principal. Hence, it cannot be used to control access based on a specific IAM role; it merely identifies the VPC, which may contain many roles and workloads.

  • ✓

    aws:PrincipalArn

    Why this is correct

    The aws:PrincipalArn condition key matches the full ARN of the IAM principal (user or role) that is making the request. For a VPC endpoint policy controlling access to Amazon S3, you can specify a role ARN as the value, ensuring only requests signed with that role's credentials are allowed through the endpoint. This is the correct way to restrict access to a specific IAM role because it directly inspects the principal identity rather than the network source.

  • ✗

    aws:username

    Why it's wrong here

    The aws:username condition key is only populated for requests made by an IAM user; it is absent for requests made by an IAM role or via temporary security credentials from an assumed role. Since the requirement is to allow a specific IAM role, aws:username cannot be used because it does not provide the role's identifier. In fact, for role-signed requests, aws:username is null, so the condition would never match.

  • ✗

    aws:SourceVpce

    Why it's wrong here

    The aws:SourceVpce condition key restricts access based on the ID of the VPC endpoint (e.g., vpce-12345678) that received the request. It is a network-origin condition, not an identity condition, so it cannot indicate which IAM role is allowed. While it can be useful to limit traffic to a particular endpoint, it is completely unrelated to the principal's ARN and therefore does not satisfy the requirement to restrict access by role.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.