SCS-C02 Management and Security Governance Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": "s3:*",
"Resource": "arn:aws:s3:::example-bucket/*",
"Condition": {
"BoolIfExists": {
"aws:SecureTransport": "false"
}
}
}
]
}Refer to the exhibit. A security engineer attaches this S3 bucket policy to an S3 bucket. What is the effect of this policy?
⚠ Common exam trap
SCS-C02 often tests the misconception that a policy needs an Allow statement to have any effect, causing candidates to select 'no effect' when a Deny-only policy is actually fully enforceable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Requests over HTTP are denied, but HTTPS requests are allowed.
The policy contains a Deny statement conditioned on 'aws:SecureTransport' being false, which blocks all HTTP requests while allowing HTTPS requests to proceed (subject to other permissions). Because Deny only triggers when the condition matches, HTTPS requests are unaffected by this statement and can be allowed by other policies or ACLs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Requests over HTTP are denied, but HTTPS requests are allowed.
Why this is correct
The bucket policy includes a Deny statement with a Bool condition on aws:SecureTransport set to "false". This condition matches only when the request is made over plain HTTP, not TLS/SSL. Consequently, HTTP requests are explicitly denied, while HTTPS requests do not match the condition and therefore are not blocked by this statement. Any valid allow from another policy can therefore permit HTTPS access.
- ✗
The policy has no effect because there is no Allow statement.
Why it's wrong here
Explicit Deny statements in IAM and S3 bucket policies are always evaluated and take precedence over any Allow statement, whether that Allow exists in the same policy or another policy. The absence of an Allow statement does not render a Deny inert; in fact, the default IAM behavior is to deny everything not explicitly allowed. Thus, this policy definitely has an effect by blocking HTTP requests.
- ✗
All requests over HTTPS are allowed.
Why it's wrong here
This statement does not contain an Allow effect, so it grants no permissions whatsoever. HTTPS requests are simply not matched by the Deny condition, but they still require an independent Allow from an IAM policy, bucket policy, or bucket ACL. Without such an allow, HTTPS requests are implicitly denied by the default S3/IAM fallback. Therefore it would be incorrect to claim that the policy allows all HTTPS traffic.
- ✗
All requests to the bucket are denied.
Why it's wrong here
The Deny statement is narrowly scoped by the aws:SecureTransport condition: it triggers only when the boolean value is "false". Requests using HTTPS are not denied because the condition evaluates to false for them, so the policy does not apply to secure connections. While the absence of an Allow statement might result in implicit denial for some principals, the explicit Deny in this policy cannot be characterized as denying all requests to the bucket, because it excludes HTTPS by design.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.