Courseiva

SCS-C02 Identity and Access Management Practice Question

A security engineer needs to restrict access to an S3 bucket so that only requests from a specific VPC endpoint are allowed. Which condition must be configured?

⚠ Common exam trap

SCS-C02 often tests the difference between `aws:SourceVpce` and `aws:SourceVpc`; candidates may confuse VPC ID with VPC endpoint ID, leading to selection of the wrong condition key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aws:SourceVpce

To restrict S3 bucket access to a specific VPC endpoint, the bucket policy must include a condition that checks the VPC endpoint ID. The condition key `aws:SourceVpce` evaluates the endpoint ID of the VPC endpoint through which the request arrives. This ensures that only requests originating from that specific endpoint are allowed, effectively blocking access from the public internet or other endpoints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aws:SourceIp

    Why it's wrong here

    aws:SourceIp evaluates the source IP address of the request, but when traffic reaches S3 through a VPC endpoint, the source IP is translated to the S3 service's internal address or the VPC endpoint's private IP, making it unverifiable. It also fails for requests originating from IPs behind a NAT gateway because the condition sees the gateway's IP, not the actual client. Consequently, aws:SourceIp is not a reliable network-restriction condition for S3 bucket policies with VPC endpoints.

  • ✗

    aws:UserAgent

    Why it's wrong here

    aws:UserAgent checks the User-Agent HTTP header, which typically identifies the client software, such as a browser or SDK, but it reveals nothing about the network path or whether the request came through a VPC endpoint. This header is entirely client-controlled and can be easily forged by any caller, making it trivial to bypass any restriction based on it. Hence, aws:UserAgent is irrelevant for restricting access to an S3 bucket by network origin.

  • ✓

    aws:SourceVpce

    Why this is correct

    aws:SourceVpce is the correct condition key because it restricts access to requests that arrive through a specific VPC endpoint, identified by its endpoint ID (e.g., vpce-1234567890abcdef0). This condition is evaluated based on the endpoint's identity, which cannot be spoofed or altered through IP address translation, providing a reliable network-level control. It ensures that only traffic coming from that exact VPC endpoint is allowed to access the S3 bucket.

  • ✗

    aws:SourceVpc

    Why it's wrong here

    aws:SourceVpc limits access to requests that originate from within a specified VPC, but it does not require that the request came through a VPC endpoint; it also allows traffic routed via an internet gateway, NAT gateway, or VPC peering connection. This makes the condition too broad if the goal is to permit only specific VPC endpoint traffic. To precisely restrict access to a particular VPC endpoint, you must use aws:SourceVpce instead.

  • ✗

    aws:Referer

    Why it's wrong here

    aws:Referer checks the HTTP Referer header, which indicates the URL of the webpage that initiated the request. This is an application-layer signal that can be easily spoofed by any custom HTTP client and does not carry any information about the underlying network path or VPC endpoint. Therefore, it cannot enforce that requests originate from a specific endpoint and is not a valid mechanism for controlling S3 bucket access at the network level.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SCS-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security engineer needs to restrict access to an S3 bucket so that only requests from a specific VPC are allowed. Which TWO steps are required?

medium
  • ✓ A.Add a bucket policy that denies access unless the request source VPC endpoint matches the created endpoint.
  • B.Add a bucket policy with aws:SourceVpc condition.
  • ✓ C.Create a VPC endpoint for S3 and attach it to the VPC.
  • D.Attach a VPC endpoint policy that allows the required actions.
  • E.Create a bucket policy that allows access from the VPC ID.

Why A: Option C is correct because to restrict S3 access to a specific VPC, you must first create a VPC endpoint (interface or gateway) for S3 and associate it with that VPC, which gives the VPC a private path to S3 and a unique endpoint ID that can be referenced in policies. Option A is correct because the bucket policy must then explicitly deny (or allow only) requests whose source matches that specific VPC endpoint, typically using the aws:sourceVpce condition key with the endpoint ID, ensuring only traffic through that endpoint can access the bucket. Option B is incorrect because aws:SourceVpc alone is not the precise condition key for endpoint-based restriction and, without the endpoint and matching policy, does not fulfill the requirement. Option D is incorrect because a VPC endpoint policy controls what the endpoint can access, not which VPC can access the bucket, so it is not a required step for this restriction. Option E is incorrect because a bucket policy allowing access by VPC ID alone is insufficient and not the mechanism used to enforce endpoint-scoped access.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.