Courseiva

SCS-C02 Identity and Access Management Practice Question

A security engineer is designing a system to manage access to an S3 bucket containing confidential data. Which TWO actions should the engineer take to implement least privilege?

⚠ Common exam trap

SCS-C02 often tests the misconception that using pre-signed URLs or object ACLs alone achieves least privilege, when in fact least privilege requires explicit, minimal IAM actions and conditions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a condition in the IAM policy to restrict access to requests from a specific IP range.

Option A is correct because adding an IAM policy condition such as aws:SourceIp to restrict requests to a specific IP range narrows the circumstances under which the allowed S3 actions can be performed, which is a core least-privilege technique. Option B is correct because granting only the specific actions required (for example s3:GetObject instead of s3:*) limits permissions to exactly what the workload needs, directly implementing least privilege. Option C is wrong because allowing s3:* for all users in the organization grants far broader permissions than necessary and violates least privilege. Option D is wrong because making the bucket public exposes the confidential data and object ACLs alone are not a least-privilege access control mechanism. Option E is wrong because pre-signed URLs are a temporary delegation mechanism, not a substitute for scoping IAM permissions to the minimum required actions and conditions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a condition in the IAM policy to restrict access to requests from a specific IP range.

    Why this is correct

    An IAM condition using aws:SourceIp restricts valid S3 requests to a specified CIDR range, ensuring credentials are only usable from your corporate or trusted network and shrinking the attack surface. This complements least-privilege actions by adding a network-layer control, but remember that if the request goes through a VPC endpoint, aws:SourceIp is not evaluated and you must use aws:sourceVpce instead. It is a valid, cost-free way to reduce exposure.

  • ✓

    Grant only the specific S3 actions needed (e.g., s3:GetObject) rather than s3:*

    Why this is correct

    Granting only the exact S3 actions an application or user requires (for example, s3:GetObject on a specific bucket and prefix rather than s3:*) is the principle of least privilege in practice. This limits the damage a compromised credential can do, preventing unauthorized list, delete, or policy-modification operations. To make it even more secure, scope the Resource to the precise bucket and ARN and add conditions like encryption requirements or MFA.

  • ✗

    Use a policy that allows s3:* for all users in the organization.

    Why it's wrong here

    Allowing s3:* for every user in the organization means each IAM principal can read, write, delete, and change access controls on any S3 bucket, which is the opposite of least privilege and creates a huge blast radius. A stolen credential for any user—even one intended for read-only or a service account—can be used to destroy or exfiltrate all data. It also eliminates the ability to audit fine-grained actions or enforce separation of duties, so this is categorically an insecure design.

  • ✗

    Make the bucket public and rely on object ACLs to restrict access.

    Why it's wrong here

    Making a bucket public while relying on object ACLs is unsafe because the bucket-level policy or ACL can unintentionally open all objects; if a later upload omits an explicit deny, the object inherits public access. AWS strongly recommends S3 Block Public Access at the account and bucket level, and using IAM or bucket policies with conditions for controlled access. ACLs are a legacy mechanism that don't support conditions such as IP restrictions or MFA, so they are not a robust security control.

  • ✗

    Use pre-signed URLs for all access to the bucket.

    Why it's wrong here

    Pre-signed URLs grant anyone who holds them temporary, time-limited access to a specific S3 object, typically for a one-off download or upload, and they are not designed to manage ongoing least-privilege access. Using them for all access requires your application to generate, distribute, and track every URL, which doesn't scale and makes central revocation difficult—you can't invalidate individual pre-signed URLs before expiration. Additionally, the URLs don't support IAM conditions like MFA or IP-based restrictions, so they should be used only for short-lived delegation, not as a primary access-management mechanism.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.