Courseiva
Infrastructure Security →mediumMultiple Choice

SCS-C02 Infrastructure Security Practice Question

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "sqs:SendMessage",
      "Resource": "arn:aws:sqs:us-east-1:123456789012:MyQueue",
      "Condition": {
        "ArnLike": {
          "aws:SourceArn": "arn:aws:sns:us-east-1:123456789012:MyTopic"
        }
      }
    },
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "sqs:ReceiveMessage",
      "Resource": "arn:aws:sqs:us-east-1:123456789012:MyQueue",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "10.0.0.0/8"
        }
      }
    }
  ]
}

A security engineer is reviewing the SQS queue policy shown in the exhibit. The queue is subscribed to an SNS topic in the same account. The security team has a requirement that only the SNS topic should be allowed to send messages to the queue. What is the issue with this policy?

⚠ Common exam trap

The trap here is that candidates may focus on the `aws:SourceArn` condition or the lack of a principal, overlooking the fact that the second statement grants broad receive access to any IP in the 10.0.0.0/8 range, which violates the requirement to restrict message sending to only the SNS topic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The second statement allows any principal in the 10.0.0.0/8 range to receive messages from the queue.

The second statement in the SQS queue policy allows any principal in the 10.0.0.0/8 IP range to receive messages from the queue, which violates the security requirement that only the SNS topic should be allowed to send messages. The policy should restrict the `sqs:SendMessage` action to the SNS topic using a condition like `aws:SourceArn` and should not include a broad `Effect: Allow` for `sqs:ReceiveMessage` without restricting the principal or source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The second statement allows any principal in the 10.0.0.0/8 range to receive messages from the queue.

    Why this is correct

    The second statement grants ReceiveMessage to Principal '*' but limits the request to the 10.0.0.0/8 network via aws:SourceIp. That condition only restricts the caller's IP address; it does not restrict which IAM principal or account can call, so any authenticated principal originating from that CIDR may receive messages. Production should scope the principal to a specific account or IAM role, or add aws:SourceArn if the intent is to allow only a single source service.

  • ✗

    The policy does not specify a principal, so it will not work.

    Why it's wrong here

    This claim is incorrect because the policy does include a Principal element; in a typical SQS access policy, both statements specify 'Principal': '*', which is valid when paired with conditions such as aws:SourceArn or aws:SourceIp. A policy without any Principal would not attach correctly, but that is not the case here. The wildcard principal does not prevent the policy from functioning; it merely expands the set of subjects, and it is acceptable only because the conditions constrain the request.

  • ✗

    The aws:SourceArn condition uses ArnLike which is deprecated.

    Why it's wrong here

    ArnLike is a standard condition operator for comparing ARNs with wildcard characters, and it is not deprecated in IAM or SQS policy evaluation. Queue policies commonly use aws:SourceArn with ArnLike, for example 'ArnLike': {'aws:SourceArn': 'arn:aws:sns:us-east-1:123456789012:topic'}. Confusion about deprecation may stem from older documentation, but ArnLike remains fully supported and is the appropriate operator for ARN pattern matching.

  • ✗

    The aws:SourceIp condition cannot be used with SQS queue policies.

    Why it's wrong here

    aws:SourceIp is a global condition key that is valid in SQS queue policies; it lets you restrict source IP addresses, such as with 'IpAddress': {'aws:SourceIp': '10.0.0.0/8'}. It is not SQS-specific, but global condition keys are available in all services that support IAM resource policies. A subtle nuance is that if requests arrive through a VPC endpoint, aws:SourceIp may not be evaluated as expected, so it is not a substitute for restricting the principal.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.