SCS-C02 IAM Policy Evaluation Practice Question
An IAM policy includes the following statement: 'Effect': 'Allow', 'Action': 's3:GetObject', 'Resource': 'arn:aws:s3:::example-bucket/*', 'Condition': {'IpAddress': {'aws:SourceIp': '192.0.2.0/24'}}. Which TWO statements about this policy are correct?
⚠ Common exam trap
SCS-C02 often tests IAM policy evaluation logic — candidates forget that a Condition on an Allow statement means requests failing the condition are implicitly denied, and they confuse GetObject with PutObject or assume the policy grants anonymous access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Requests from outside 192.0.2.0/24 will be implicitly denied.
Option E is correct because the statement's Action is s3:GetObject and its Condition restricts aws:SourceIp to 192.0.2.0/24, so the allow applies exactly to GetObject requests originating from that CIDR range. Option B is correct because IAM policies are deny-by-default: any request that does not satisfy the IpAddress condition (i.e., comes from outside 192.0.2.0/24) is not matched by this Allow and is therefore implicitly denied, absent another applicable allow. Option A is wrong because s3:PutObject is not listed in the Action, so the policy never grants write access. Option C is wrong because there is no condition on bucket ownership; the only condition is the source IP. Option D is wrong because the policy grants no anonymous/public access by itself—it only allows GetObject when the request's source IP falls in the specified range, and it does not remove authentication requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy allows s3:PutObject from the IP range 192.0.2.0/24.
Why it's wrong here
This statement's Action element is specifically s3:GetObject, not s3:PutObject, so the Allow effect only applies to reading objects. PutObject would require its own separate Allow statement or a wildcard in the Action. Any PutObject attempt, regardless of source IP, falls under the default implicit deny because no statement grants it.
- ✓
Requests from outside 192.0.2.0/24 will be implicitly denied.
Why this is correct
This is correct because an IAM policy's Allow effect only takes effect when all conditions are satisfied. The IpAddress condition restricts valid source IPs to 192.0.2.0/24; if a request originates outside that range, the condition fails and the Allow does not apply. Since no other statement explicitly allows the action, the request is implicitly denied by default.
- ✗
The policy allows s3:GetObject only if the bucket owner matches.
Why it's wrong here
The policy contains no condition related to bucket ownership, such as s3:ResourceAccount or s3:ExpectedBucketOwner. Its only condition is on the source IP address, so ownership is irrelevant to this statement. Even if the bucket owner differs from the principal, the policy only controls whether GetObject is permitted from the specified IP range.
- ✗
The policy allows anonymous access.
Why it's wrong here
IAM policies are attached to authenticated IAM principals—users, groups, or roles—and cannot be used to grant permissions to anonymous, unauthenticated identities. Anonymous access in Amazon S3 is granted only through bucket policies that specify Principal: "*" without an authentication layer. Since this statement is an IAM policy, it inherently applies only to authenticated principals.
- ✓
The policy allows s3:GetObject from the IP range 192.0.2.0/24.
Why this is correct
This is correct: the statement sets Effect to Allow, Action to s3:GetObject, and includes a condition using IpAddress that restricts the request source IP to 192.0.2.0/24. When a request matches the action, resource, and satisfies the IP condition, the Allow applies. Requests from inside that range are explicitly permitted as long as all other policy requirements are met.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.