SCS-C02 Identity and Access Management Practice Question
Exhibit
Refer to the exhibit.
```
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::example-bucket/*",
"Condition": {
"StringEquals": {
"s3:x-amz-server-side-encryption": "aws:kms"
}
}
}
]
}
```Refer to the exhibit. An IAM policy allows s3:GetObject on an S3 bucket only when the object is encrypted with SSE-KMS. An IAM user with this policy attempts to download an object that is not encrypted. What will happen?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The download fails because the condition is not met, even though the action is allowed.
The policy allows s3:GetObject only when the condition (SSE-KMS encryption) is met. Since the object is not encrypted with SSE-KMS, the condition fails, the allow does not apply, and the request is implicitly denied. Option B is incorrect because the condition is required for the allow to take effect. Option C is incorrect because the policy is syntactically valid. Option D is incorrect because the absence of an explicit deny does not grant permission; the allow condition must still be satisfied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The download fails because the condition is not met, even though the action is allowed.
Why this is correct
The request does not satisfy the condition placed on the Allow, so the policy engine cannot produce an effective Allow for this operation. AWS evaluates IAM condition blocks as part of determining whether a statement applies, and a false condition causes the statement to be skipped entirely. Consequently, the s3:GetObject action is denied by default even though the statement text appears to authorize the action.
- ✗
The download succeeds because the condition is not required.
Why it's wrong here
This answer assumes the Condition block is advisory, but IAM treats it as a hard requirement: every condition in the statement must evaluate to true for the Allow to be granted. If the condition is missing from the request context or evaluates to false, the policy statement does not match the request and contributes no permissions. There is no concept of a "non-required" condition that can be ignored during evaluation.
- ✗
The download fails because the policy is invalid.
Why it's wrong here
The policy is not invalid because all required IAM policy elements—Effect, Action, Resource, and Condition—are present and use supported operators and ARNs. A syntactically valid policy can still fail to grant access when the Condition is not satisfied; that is a logical evaluation issue, not a policy validation failure. The IAM policy validator would not reject this statement, so the download failure is unrelated to invalidity.
- ✗
The download succeeds because there is no explicit deny.
Why it's wrong here
IAM authorization does not work by default permit; if no Allow statement applies, the request is implicitly denied no matter how few explicit Deny statements exist. The presence or absence of an explicit deny is only relevant after an applicable Allow has been found, because Deny is an override, not a grant. Here, since the condition on the only Allow is false, no applicable Allow exists, so the download is denied without requiring an explicit deny.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.