Courseiva

SCS-C02 Identity and Access Management Practice Question

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:GetObject"],
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": [
            "192.0.2.0/24",
            "198.51.100.0/24"
          ]
        },
        "Bool": {
          "aws:SecureTransport": "true"
        }
      }
    }
  ]
}

Refer to the exhibit. An IAM policy is attached to a group. A user in the group accesses the S3 bucket from an IP address 203.0.113.5 using HTTPS. What will be the result?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user will be denied access because the source IP is not in the allowed ranges.

The IAM policy includes a condition that restricts access to only the IP ranges 192.0.2.0/24 and 198.51.100.0/24. The user's IP address 203.0.113.5 does not fall within these ranges, so access is denied. Option B is incorrect because an Allow with conditions does not grant access by default; all conditions must be satisfied. Option C is incorrect because the policy does explicitly allow the s3:GetObject action, but only under the specified conditions. Option D is incorrect because while SecureTransport is satisfied, the IP condition is not met, and all conditions must be true for the Allow to take effect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The user will be denied access because the source IP is not in the allowed ranges.

    Why this is correct

    Because the only Allow statement in the attached group policy is conditioned on both a permitted source IP range and HTTPS (SecureTransport=true), a request coming from an IP outside that range does not satisfy the source IP condition. In IAM evaluation, an Allow with unsatisfied conditions contributes no effective permission, and since no other applicable statement grants the action, the default-deny rule applies. The user is therefore denied even though HTTPS might be used.

  • ✗

    The user can access objects because an Allow with conditions grants access by default.

    Why it's wrong here

    AWS IAM never grants access by default; any request starts with an implicit deny. A statement such as Allow s3:GetObject with a condition only applies when the condition evaluates to true, so the presence of an Allow with conditions is not sufficient by itself. Since the request does not meet the IP condition, the Allow does not match, so the user cannot access the object.

  • ✗

    The user will be denied access because the policy does not allow the action explicitly.

    Why it's wrong here

    This policy does contain an explicit Allow for the action, so saying it fails because the action is not allowed is factually wrong. The denial is not caused by a missing permit but by the policy's condition block: the action is allowed only under certain conditions. Because the source IP is outside the permitted ranges, the Allow statement is filtered out and the implicit deny takes effect.

  • ✗

    The user can access objects because the condition for SecureTransport is met.

    Why it's wrong here

    The SecureTransport condition is indeed part of the statement, and if the user made the request over HTTPS that condition is true. However, IAM condition blocks apply all provided condition keys with logical AND; every key must match before the Allow is granted. The source IP condition is not met, so the request is denied despite the satisfied SecureTransport condition.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.