SCS-C02 Data Protection Practice Question
Network Topology
Refer to the exhibit. A security engineer reviews the bucket policy for an S3 bucket. The engineer attempts to upload an object to the bucket using the AWS CLI without the --ssl flag (HTTP). What is the outcome?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The upload fails because the policy denies requests that are not using HTTPS.
The bucket policy includes a condition that explicitly denies all s3: actions (including s3:PutObject) when the request does not use HTTPS (SecureTransport is false). Since the engineer uses HTTP (no --ssl flag), the condition is met, and the upload is denied. Option A is incorrect because the policy does not allow all actions; it includes a conditional deny. Option C is incorrect because default encryption does not override the explicit deny in the policy. Option D is incorrect because the policy denies all s3 actions, not just s3:PutObject.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The upload succeeds because the policy allows all actions.
Why it's wrong here
The statement in the exhibit is an explicit Deny, not an Allow, so it cannot make uploads succeed. When a request comes in over HTTP, the condition aws:SecureTransport=false matches and the Deny blocks the action. Even if there were other Allow statements, an explicit Deny always overrides them, so the action is still not permitted.
- ✓
The upload fails because the policy denies requests that are not using HTTPS.
Why this is correct
The bucket policy contains a Deny statement targeting all S3 actions and keyed on the Bool condition aws:SecureTransport=false. Requests made with HTTP set this key to false, so the condition evaluates true, the Deny is applied, and the PutObject upload is rejected. Only HTTPS requests would have SecureTransport=true and therefore would not match this particular Deny; however, an explicit Allow statement is still required to authorize the request.
- ✗
The upload succeeds because the bucket has default encryption enabled.
Why it's wrong here
Default encryption only addresses server-side encryption of objects at rest; it has no effect on how requests are transported or on the evaluation of aws:SecureTransport. The Deny in the bucket policy unconditionally blocks requests where the condition is satisfied, regardless of whether the bucket has default encryption applied. Therefore, enabling default encryption cannot cause an HTTP upload to succeed, because the transport-level Deny still triggers before object storage is considered.
- ✗
The upload fails because the policy denies s3:PutObject only.
Why it's wrong here
The Deny statement is configured with the Action value s3:*, which means it applies to every S3 API operation, including GetObject, ListBucket, and PutObject, when the SecureTransport condition is false. Limiting the explanation to only s3:PutObject is inaccurate because it ignores the wildcard coverage and the other actions that are also denied. The reason the upload fails is not because PutObject alone is denied, but because all S3 actions are denied for non-HTTPS requests.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.