Courseiva

SCS-C02 IAM Policy Evaluation Practice Question

An IAM policy includes the following statement: 'Effect': 'Allow', 'Action': 's3:GetObject', 'Resource': 'arn:aws:s3:::example-bucket/*', 'Condition': {'IpAddress': {'aws:SourceIp': '192.0.2.0/24'}}. Which TWO statements about this policy are correct?

⚠ Common exam trap

SCS-C02 often tests IAM policy evaluation logic — candidates forget that a Condition on an Allow statement means requests failing the condition are implicitly denied, and they confuse GetObject with PutObject or assume the policy grants anonymous access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Requests from outside 192.0.2.0/24 will be implicitly denied.

Option E is correct because the statement's Action is s3:GetObject and its Condition restricts aws:SourceIp to 192.0.2.0/24, so the allow applies exactly to GetObject requests originating from that CIDR range. Option B is correct because IAM policies are deny-by-default: any request that does not satisfy the IpAddress condition (i.e., comes from outside 192.0.2.0/24) is not matched by this Allow and is therefore implicitly denied, absent another applicable allow. Option A is wrong because s3:PutObject is not listed in the Action, so the policy never grants write access. Option C is wrong because there is no condition on bucket ownership; the only condition is the source IP. Option D is wrong because the policy grants no anonymous/public access by itself—it only allows GetObject when the request's source IP falls in the specified range, and it does not remove authentication requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy allows s3:PutObject from the IP range 192.0.2.0/24.

    Why it's wrong here

    This statement's Action element is specifically s3:GetObject, not s3:PutObject, so the Allow effect only applies to reading objects. PutObject would require its own separate Allow statement or a wildcard in the Action. Any PutObject attempt, regardless of source IP, falls under the default implicit deny because no statement grants it.

  • ✓

    Requests from outside 192.0.2.0/24 will be implicitly denied.

    Why this is correct

    This is correct because an IAM policy's Allow effect only takes effect when all conditions are satisfied. The IpAddress condition restricts valid source IPs to 192.0.2.0/24; if a request originates outside that range, the condition fails and the Allow does not apply. Since no other statement explicitly allows the action, the request is implicitly denied by default.

  • ✗

    The policy allows s3:GetObject only if the bucket owner matches.

    Why it's wrong here

    The policy contains no condition related to bucket ownership, such as s3:ResourceAccount or s3:ExpectedBucketOwner. Its only condition is on the source IP address, so ownership is irrelevant to this statement. Even if the bucket owner differs from the principal, the policy only controls whether GetObject is permitted from the specified IP range.

  • ✗

    The policy allows anonymous access.

    Why it's wrong here

    IAM policies are attached to authenticated IAM principals—users, groups, or roles—and cannot be used to grant permissions to anonymous, unauthenticated identities. Anonymous access in Amazon S3 is granted only through bucket policies that specify Principal: "*" without an authentication layer. Since this statement is an IAM policy, it inherently applies only to authenticated principals.

  • ✓

    The policy allows s3:GetObject from the IP range 192.0.2.0/24.

    Why this is correct

    This is correct: the statement sets Effect to Allow, Action to s3:GetObject, and includes a condition using IpAddress that restricts the request source IP to 192.0.2.0/24. When a request matches the action, resource, and satisfies the IP condition, the Allow applies. Requests from inside that range are explicitly permitted as long as all other policy requirements are met.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.