SCS-C02 Identity and Access Management Practice Question
An IAM policy has the following statement: {"Effect":"Deny","Action":"*","Resource":"*","Condition":{"Bool":{"aws:SecureTransport":"false"}}}. What does this policy achieve?
⚠ Common exam trap
Test-takers frequently confuse a `Deny` with a `Bool` condition as an implicit `Allow` for the opposite condition, but the policy only denies non-HTTPS requests and does not grant any explicit allow, so all actions are allowed by default when HTTPS is used.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Denies all actions that are not made over HTTPS
This policy statement uses the `aws:SecureTransport` condition key with a `Bool` condition set to `false`. When the condition evaluates to true (i.e., the request is not using HTTPS/TLS), the `Deny` effect applies to all actions on all resources. This effectively denies any API call made over HTTP (non-secure transport), ensuring that only HTTPS requests are allowed. The policy does not explicitly allow anything; it only denies non-HTTPS traffic, so all actions are implicitly allowed when made over HTTPS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Denies all actions that are not made over HTTPS
Why this is correct
This IAM policy statement uses a Deny effect with the aws:SecureTransport condition key set to 'false', so it blocks any API call that was not transmitted over a TLS/HTTPS connection. Because an explicit Deny takes precedence over all Allow statements, the policy stops every non-HTTPS request to any AWS service, while leaving HTTPS requests unaffected. The condition applies to the transport-layer security of the request itself, not to the specific action or resource, making the statement a global enforcement of HTTPS for all AWS API operations.
- ✗
Allows all actions only when using HTTPS
Why it's wrong here
The statement's Effect is Deny, not Allow, so it can never grant access to any action, even one made over HTTPS. A policy with this effect merely creates a restriction that blocks non-HTTPS calls; authorizing HTTPS requests requires a separate, explicit Allow statement. Conflating the Deny with an Allow is a common misunderstanding, but an IAM policy cannot implicitly allow an action when it is written as a Deny. This option incorrectly describes the statement as a positive authorization when it is purely a prohibition.
- ✗
Enforces HTTPS for S3 bucket policies only
Why it's wrong here
This is an IAM identity-based policy, not an S3 bucket policy, and the aws:SecureTransport condition key can be used across all AWS services and policy types. When you attach this policy to an IAM user or role, it enforces HTTPS for every service that identity calls, including EC2, Lambda, DynamoDB, and others, not just S3. S3 bucket policies are resource-based and scope the condition to a specific bucket, but this policy is not scoped to S3 resources. Therefore, it does not apply exclusively to S3 bucket policies.
- ✗
Blocks all actions for a specific AWS service
Why it's wrong here
This policy does not target any one AWS service; it uses a wildcard in the Action clause (e.g., 'Action':'*') and a wildcard Resource, so it applies to all services, all resources, and all operations. A service-specific block would require actions to be namespaced to that service (e.g., 's3:PutObject' or 'ec2:*'), and the resource to be restricted accordingly. Since the policy is not limited to a service namespace, it denies non-HTTPS requests across every service rather than only one. This option incorrectly narrows the scope of what is actually a broad, account-wide restriction.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.