Courseiva
Data Protection →easyMultiple Choice

SCS-C02 Data Protection Practice Question

Network Topology
$ aws s3api get-bucket-policybucket my-secure-bucketRefer to the exhibit."Policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Deny\",\"Principal\":\"*\",\"Action\":\"s3:*\",\"Resource\":\"arn:aws:s3:::my-secure-bucket/*\",\"Condition\":{\"Bool\":{\"aws:SecureTransport\":\"false\"}}}]}"

Refer to the exhibit. A security engineer reviews the bucket policy for an S3 bucket. The engineer attempts to upload an object to the bucket using the AWS CLI without the --ssl flag (HTTP). What is the outcome?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The upload fails because the policy denies requests that are not using HTTPS.

The bucket policy includes a condition that explicitly denies all s3: actions (including s3:PutObject) when the request does not use HTTPS (SecureTransport is false). Since the engineer uses HTTP (no --ssl flag), the condition is met, and the upload is denied. Option A is incorrect because the policy does not allow all actions; it includes a conditional deny. Option C is incorrect because default encryption does not override the explicit deny in the policy. Option D is incorrect because the policy denies all s3 actions, not just s3:PutObject.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The upload succeeds because the policy allows all actions.

    Why it's wrong here

    The statement in the exhibit is an explicit Deny, not an Allow, so it cannot make uploads succeed. When a request comes in over HTTP, the condition aws:SecureTransport=false matches and the Deny blocks the action. Even if there were other Allow statements, an explicit Deny always overrides them, so the action is still not permitted.

  • ✓

    The upload fails because the policy denies requests that are not using HTTPS.

    Why this is correct

    The bucket policy contains a Deny statement targeting all S3 actions and keyed on the Bool condition aws:SecureTransport=false. Requests made with HTTP set this key to false, so the condition evaluates true, the Deny is applied, and the PutObject upload is rejected. Only HTTPS requests would have SecureTransport=true and therefore would not match this particular Deny; however, an explicit Allow statement is still required to authorize the request.

  • ✗

    The upload succeeds because the bucket has default encryption enabled.

    Why it's wrong here

    Default encryption only addresses server-side encryption of objects at rest; it has no effect on how requests are transported or on the evaluation of aws:SecureTransport. The Deny in the bucket policy unconditionally blocks requests where the condition is satisfied, regardless of whether the bucket has default encryption applied. Therefore, enabling default encryption cannot cause an HTTP upload to succeed, because the transport-level Deny still triggers before object storage is considered.

  • ✗

    The upload fails because the policy denies s3:PutObject only.

    Why it's wrong here

    The Deny statement is configured with the Action value s3:*, which means it applies to every S3 API operation, including GetObject, ListBucket, and PutObject, when the SecureTransport condition is false. Limiting the explanation to only s3:PutObject is inaccurate because it ignores the wildcard coverage and the other actions that are also denied. The reason the upload fails is not because PutObject alone is denied, but because all S3 actions are denied for non-HTTPS requests.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.