Courseiva

SCS-C02 Identity and Access Management Practice Question

An IAM policy has the following statement: {"Effect":"Deny","Action":"*","Resource":"*","Condition":{"Bool":{"aws:SecureTransport":"false"}}}. What does this policy achieve?

⚠ Common exam trap

Test-takers frequently confuse a `Deny` with a `Bool` condition as an implicit `Allow` for the opposite condition, but the policy only denies non-HTTPS requests and does not grant any explicit allow, so all actions are allowed by default when HTTPS is used.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Denies all actions that are not made over HTTPS

This policy statement uses the `aws:SecureTransport` condition key with a `Bool` condition set to `false`. When the condition evaluates to true (i.e., the request is not using HTTPS/TLS), the `Deny` effect applies to all actions on all resources. This effectively denies any API call made over HTTP (non-secure transport), ensuring that only HTTPS requests are allowed. The policy does not explicitly allow anything; it only denies non-HTTPS traffic, so all actions are implicitly allowed when made over HTTPS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Denies all actions that are not made over HTTPS

    Why this is correct

    This IAM policy statement uses a Deny effect with the aws:SecureTransport condition key set to 'false', so it blocks any API call that was not transmitted over a TLS/HTTPS connection. Because an explicit Deny takes precedence over all Allow statements, the policy stops every non-HTTPS request to any AWS service, while leaving HTTPS requests unaffected. The condition applies to the transport-layer security of the request itself, not to the specific action or resource, making the statement a global enforcement of HTTPS for all AWS API operations.

  • ✗

    Allows all actions only when using HTTPS

    Why it's wrong here

    The statement's Effect is Deny, not Allow, so it can never grant access to any action, even one made over HTTPS. A policy with this effect merely creates a restriction that blocks non-HTTPS calls; authorizing HTTPS requests requires a separate, explicit Allow statement. Conflating the Deny with an Allow is a common misunderstanding, but an IAM policy cannot implicitly allow an action when it is written as a Deny. This option incorrectly describes the statement as a positive authorization when it is purely a prohibition.

  • ✗

    Enforces HTTPS for S3 bucket policies only

    Why it's wrong here

    This is an IAM identity-based policy, not an S3 bucket policy, and the aws:SecureTransport condition key can be used across all AWS services and policy types. When you attach this policy to an IAM user or role, it enforces HTTPS for every service that identity calls, including EC2, Lambda, DynamoDB, and others, not just S3. S3 bucket policies are resource-based and scope the condition to a specific bucket, but this policy is not scoped to S3 resources. Therefore, it does not apply exclusively to S3 bucket policies.

  • ✗

    Blocks all actions for a specific AWS service

    Why it's wrong here

    This policy does not target any one AWS service; it uses a wildcard in the Action clause (e.g., 'Action':'*') and a wildcard Resource, so it applies to all services, all resources, and all operations. A service-specific block would require actions to be namespaced to that service (e.g., 's3:PutObject' or 'ec2:*'), and the resource to be restricted accordingly. Since the policy is not limited to a service namespace, it denies non-HTTPS requests across every service rather than only one. This option incorrectly narrows the scope of what is actually a broad, account-wide restriction.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.