Courseiva

SCS-C02 Identity and Access Management Practice Question

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "StringEquals": {
          "s3:x-amz-server-side-encryption": "aws:kms"
        }
      }
    }
  ]
}
```

Refer to the exhibit. An IAM policy allows s3:GetObject on an S3 bucket only when the object is encrypted with SSE-KMS. An IAM user with this policy attempts to download an object that is not encrypted. What will happen?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The download fails because the condition is not met, even though the action is allowed.

The policy allows s3:GetObject only when the condition (SSE-KMS encryption) is met. Since the object is not encrypted with SSE-KMS, the condition fails, the allow does not apply, and the request is implicitly denied. Option B is incorrect because the condition is required for the allow to take effect. Option C is incorrect because the policy is syntactically valid. Option D is incorrect because the absence of an explicit deny does not grant permission; the allow condition must still be satisfied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The download fails because the condition is not met, even though the action is allowed.

    Why this is correct

    The request does not satisfy the condition placed on the Allow, so the policy engine cannot produce an effective Allow for this operation. AWS evaluates IAM condition blocks as part of determining whether a statement applies, and a false condition causes the statement to be skipped entirely. Consequently, the s3:GetObject action is denied by default even though the statement text appears to authorize the action.

  • ✗

    The download succeeds because the condition is not required.

    Why it's wrong here

    This answer assumes the Condition block is advisory, but IAM treats it as a hard requirement: every condition in the statement must evaluate to true for the Allow to be granted. If the condition is missing from the request context or evaluates to false, the policy statement does not match the request and contributes no permissions. There is no concept of a "non-required" condition that can be ignored during evaluation.

  • ✗

    The download fails because the policy is invalid.

    Why it's wrong here

    The policy is not invalid because all required IAM policy elements—Effect, Action, Resource, and Condition—are present and use supported operators and ARNs. A syntactically valid policy can still fail to grant access when the Condition is not satisfied; that is a logical evaluation issue, not a policy validation failure. The IAM policy validator would not reject this statement, so the download failure is unrelated to invalidity.

  • ✗

    The download succeeds because there is no explicit deny.

    Why it's wrong here

    IAM authorization does not work by default permit; if no Allow statement applies, the request is implicitly denied no matter how few explicit Deny statements exist. The presence or absence of an explicit deny is only relevant after an applicable Allow has been found, because Deny is an override, not a grant. Here, since the condition on the only Allow is false, no applicable Allow exists, so the download is denied without requiring an explicit deny.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.