SCS-C02 Infrastructure Security Practice Question
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-secret-bucket/*",
"Condition": {
"IpAddress": {
"aws:SourceIp": "10.0.0.0/8"
}
}
},
{
"Effect": "Deny",
"Action": "s3:*",
"Resource": "arn:aws:s3:::my-secret-bucket/*",
"Condition": {
"Bool": {
"aws:SecureTransport": "false"
}
}
}
]
}Refer to the exhibit. A user from IP 10.1.2.3 attempts to download an object from my-secret-bucket using HTTP (not HTTPS). What will be the outcome?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Failure, because the Deny statement blocks HTTP requests.
The Deny statement with condition aws:SecureTransport=false will block HTTP requests. Even though the IP matches the allow rule, the explicit Deny overrides the Allow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Success, because the Allow statement is evaluated first.
Why it's wrong here
This option assumes IAM rules are processed sequentially like a script, but AWS evaluates all applicable policies together without prioritizing the order of statements. An explicit Deny statement overrides any Allow statement regardless of where it appears in the policy document, so even if the Allow were considered first, the Deny for non-SecureTransport HTTP requests still blocks access. Therefore, the request does not succeed.
- ✗
Failure, because the user's IP is not in the allowed range.
Why it's wrong here
This option misidentifies the cause of failure. The user's IP address 10.1.2.3 is explicitly included in the allowed CIDR range in the Allow statement, so the IP condition is fully satisfied. The failure occurs because the Deny statement targeting non-SecureTransport (HTTP requests) matches the user's request, and that explicit deny takes precedence over the IP-based allowance.
- ✗
Success, because the user's IP is within the allowed range.
Why it's wrong here
It is true that the user's IP within the allowed range satisfies the condition of the Allow statement, which would normally grant permission. However, the same policy evaluation also finds a Deny statement that applies to HTTP requests through the aws:SecureTransport condition, and an explicit Deny always overrides an allowed action. Thus, the request is denied despite the IP match; the IP is not the deciding factor.
- ✓
Failure, because the Deny statement blocks HTTP requests.
Why this is correct
This is the correct outcome because AWS IAM uses an explicit deny override model: if any applicable policy contains a Deny statement that matches the request, access is denied even if an Allow statement also matches. Here, the request is sent over HTTP, so the Deny condition on aws:SecureTransport (e.g., "aws:SecureTransport": "false") is triggered, blocking the request. The user's IP being within the allowed range is irrelevant because the Deny statement takes unconditional precedence.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.