SCS-C02 Management and Security Governance Practice Question
A security engineer is configuring an S3 bucket policy to restrict access to only requests that originate from a specific VPC endpoint. Which condition key should be used?
⚠ Common exam trap
SCS-C02 often tests the confusion between aws:SourceVpc (the VPC ID) and aws:SourceVpce (the endpoint ID), tricking candidates into choosing the broader VPC-level condition when the question specifically asks to restrict to a VPC endpoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aws:SourceVpce
The aws:SourceVpce condition key is the correct choice because it evaluates the VPC endpoint ID (e.g., vpce-12345678) through which the request reached S3. When you attach a bucket policy that includes a condition like "aws:SourceVpce": "vpce-abc123", S3 only allows requests that traverse that specific endpoint, effectively locking the bucket to your private VPC endpoint and blocking all public internet access. This is the standard pattern for enforcing private-only access to S3 from a VPC.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aws:VpcSourceIp
Why it's wrong here
This condition key does not exist in the AWS IAM or S3 policy condition key namespace. AWS provides aws:SourceIp, aws:SourceVpc, and aws:SourceVpce as the relevant global condition keys for network-origin controls, but aws:VpcSourceIp is not a recognized key. Using an unknown condition key in a policy causes the condition to evaluate to false, so all requests are denied, making it impossible to use for allowing VPC endpoint access.
- ✗
aws:SourceVpc
Why it's wrong here
aws:SourceVpc is a valid global condition key that matches the VPC ID from which a request originates. However, it only tells you the VPC, not whether the request came through a specific VPC endpoint; traffic from an internet gateway, NAT gateway, VPN, or Direct Connect in the same VPC would also satisfy the condition. For restricting access to a single, specific VPC endpoint, aws:SourceVpc is too broad because it does not identify the endpoint ID.
- ✗
aws:SourceIp
Why it's wrong here
aws:SourceIp filters based on the source IP address of the requester, which is not a reliable indicator of VPC endpoint usage. When an S3 gateway endpoint is used, the source IP is typically the private IP of the EC2 instance making the request, not the endpoint's address, and that same IP could be used for traffic leaving the VPC through a NAT device or other route. IP-based conditions also break if the instance's IP changes or if other clients on the allowed IP can reach the bucket, so aws:SourceIp cannot prove the request went through the intended VPC endpoint.
- ✓
aws:SourceVpce
Why this is correct
aws:SourceVpce is the correct condition key because it directly evaluates the VPC endpoint ID (for example, vpce-0123abc) from which the S3 request originated. Combining a bucket policy that allows a principal like "*" with the condition "aws:SourceVpce": "vpce-0123abc" ensures the bucket is accessible only via that specific gateway or interface endpoint. Requests from the internet, other endpoints, or on-premises networks do not have the matching SourceVpce value and are denied, giving you precise, endpoint-level access control.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.