SCS-C02 Identity and Access Management Practice Question
A security engineer is designing a system to manage access to an S3 bucket containing confidential data. Which TWO actions should the engineer take to implement least privilege?
⚠ Common exam trap
SCS-C02 often tests the misconception that using pre-signed URLs or object ACLs alone achieves least privilege, when in fact least privilege requires explicit, minimal IAM actions and conditions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a condition in the IAM policy to restrict access to requests from a specific IP range.
Option A is correct because adding an IAM policy condition such as aws:SourceIp to restrict requests to a specific IP range narrows the circumstances under which the allowed S3 actions can be performed, which is a core least-privilege technique. Option B is correct because granting only the specific actions required (for example s3:GetObject instead of s3:*) limits permissions to exactly what the workload needs, directly implementing least privilege. Option C is wrong because allowing s3:* for all users in the organization grants far broader permissions than necessary and violates least privilege. Option D is wrong because making the bucket public exposes the confidential data and object ACLs alone are not a least-privilege access control mechanism. Option E is wrong because pre-signed URLs are a temporary delegation mechanism, not a substitute for scoping IAM permissions to the minimum required actions and conditions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a condition in the IAM policy to restrict access to requests from a specific IP range.
Why this is correct
An IAM condition using aws:SourceIp restricts valid S3 requests to a specified CIDR range, ensuring credentials are only usable from your corporate or trusted network and shrinking the attack surface. This complements least-privilege actions by adding a network-layer control, but remember that if the request goes through a VPC endpoint, aws:SourceIp is not evaluated and you must use aws:sourceVpce instead. It is a valid, cost-free way to reduce exposure.
- ✓
Grant only the specific S3 actions needed (e.g., s3:GetObject) rather than s3:*
Why this is correct
Granting only the exact S3 actions an application or user requires (for example, s3:GetObject on a specific bucket and prefix rather than s3:*) is the principle of least privilege in practice. This limits the damage a compromised credential can do, preventing unauthorized list, delete, or policy-modification operations. To make it even more secure, scope the Resource to the precise bucket and ARN and add conditions like encryption requirements or MFA.
- ✗
Use a policy that allows s3:* for all users in the organization.
Why it's wrong here
Allowing s3:* for every user in the organization means each IAM principal can read, write, delete, and change access controls on any S3 bucket, which is the opposite of least privilege and creates a huge blast radius. A stolen credential for any user—even one intended for read-only or a service account—can be used to destroy or exfiltrate all data. It also eliminates the ability to audit fine-grained actions or enforce separation of duties, so this is categorically an insecure design.
- ✗
Make the bucket public and rely on object ACLs to restrict access.
Why it's wrong here
Making a bucket public while relying on object ACLs is unsafe because the bucket-level policy or ACL can unintentionally open all objects; if a later upload omits an explicit deny, the object inherits public access. AWS strongly recommends S3 Block Public Access at the account and bucket level, and using IAM or bucket policies with conditions for controlled access. ACLs are a legacy mechanism that don't support conditions such as IP restrictions or MFA, so they are not a robust security control.
- ✗
Use pre-signed URLs for all access to the bucket.
Why it's wrong here
Pre-signed URLs grant anyone who holds them temporary, time-limited access to a specific S3 object, typically for a one-off download or upload, and they are not designed to manage ongoing least-privilege access. Using them for all access requires your application to generate, distribute, and track every URL, which doesn't scale and makes central revocation difficult—you can't invalidate individual pre-signed URLs before expiration. Additionally, the URLs don't support IAM conditions like MFA or IP-based restrictions, so they should be used only for short-lived delegation, not as a primary access-management mechanism.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.