Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

Exhibit

Refer to the exhibit.

S3 bucket policy:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Principal": "*",
      "Action": "s3:PutObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "Bool": {
          "aws:SecureTransport": "false"
        }
      }
    }
  ]
}

Refer to the exhibit. A security engineer applies this S3 bucket policy to an S3 bucket. The bucket contains sensitive data. What is the effect of this policy?

⚠ Common exam trap

SCS-C02 often tests the confusion between encryption in transit (SecureTransport/HTTPS) and encryption at rest (SSE headers), so candidates pick the at-rest encryption option when the policy actually enforces TLS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It denies PutObject requests that are not using HTTPS.

The bucket policy uses a Deny effect with a condition on 'aws:SecureTransport' set to false, which blocks any PutObject request made over plain HTTP. Requests over HTTPS satisfy the condition (SecureTransport = true), so they are not denied by this statement. This is the standard pattern for enforcing encryption in transit for S3 uploads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It allows anonymous users to upload objects.

    Why it's wrong here

    This statement uses the Effect of Deny, not Allow, so it cannot grant anyone, including anonymous users, permission to call s3:PutObject. A positive Allow with a Principal of '*' would be required to permit unauthenticated uploads, but this policy only contains a conditional Deny. The policy's effect is to block non-HTTPS requests, not to grant upload access, so the option misinterprets the direction of permission evaluation.

  • ✓

    It denies PutObject requests that are not using HTTPS.

    Why this is correct

    With the condition key aws:SecureTransport set to false, the Deny effect triggers only when the request travels over plain HTTP. Since the Action is limited to s3:PutObject, only object uploads are blocked; other operations remain unaffected. The result is that any PUT request without TLS is rejected, effectively mandating HTTPS for uploads to the bucket while still allowing secure uploads to proceed.

  • ✗

    It denies all PutObject requests to the bucket.

    Why it's wrong here

    The Deny in this policy is conditional, not absolute. If SecureTransport is true—meaning the request uses HTTPS—the condition "false" evaluates to false and the Deny statement does not apply. Thus, properly authenticated HTTPS PutObject requests succeed, proving the policy does not deny all PutObject requests; it only denies those that are insecurely transmitted.

  • ✗

    It enforces that all objects must be encrypted at rest.

    Why it's wrong here

    The policy contains no encryption-related condition keys such as s3:x-amz-server-side-encryption or s3:x-amz-server-side-encryption-aws-kms-key-id. Enforcing encryption at rest would require a Deny that checks for the absence of an encryption header, or a bucket default encryption setting with a separate deny of "null" encryption. Mere enforcement of HTTPS for uploads addresses transit security, not how data is encrypted once stored.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.