SCS-C02 Identity and Access Management Practice Question
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:GetObject"],
"Resource": "arn:aws:s3:::example-bucket/*",
"Condition": {
"IpAddress": {
"aws:SourceIp": [
"192.0.2.0/24",
"198.51.100.0/24"
]
},
"Bool": {
"aws:SecureTransport": "true"
}
}
}
]
}Refer to the exhibit. An IAM policy is attached to a group. A user in the group accesses the S3 bucket from an IP address 203.0.113.5 using HTTPS. What will be the result?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The user will be denied access because the source IP is not in the allowed ranges.
The IAM policy includes a condition that restricts access to only the IP ranges 192.0.2.0/24 and 198.51.100.0/24. The user's IP address 203.0.113.5 does not fall within these ranges, so access is denied. Option B is incorrect because an Allow with conditions does not grant access by default; all conditions must be satisfied. Option C is incorrect because the policy does explicitly allow the s3:GetObject action, but only under the specified conditions. Option D is incorrect because while SecureTransport is satisfied, the IP condition is not met, and all conditions must be true for the Allow to take effect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The user will be denied access because the source IP is not in the allowed ranges.
Why this is correct
Because the only Allow statement in the attached group policy is conditioned on both a permitted source IP range and HTTPS (SecureTransport=true), a request coming from an IP outside that range does not satisfy the source IP condition. In IAM evaluation, an Allow with unsatisfied conditions contributes no effective permission, and since no other applicable statement grants the action, the default-deny rule applies. The user is therefore denied even though HTTPS might be used.
- ✗
The user can access objects because an Allow with conditions grants access by default.
Why it's wrong here
AWS IAM never grants access by default; any request starts with an implicit deny. A statement such as Allow s3:GetObject with a condition only applies when the condition evaluates to true, so the presence of an Allow with conditions is not sufficient by itself. Since the request does not meet the IP condition, the Allow does not match, so the user cannot access the object.
- ✗
The user will be denied access because the policy does not allow the action explicitly.
Why it's wrong here
This policy does contain an explicit Allow for the action, so saying it fails because the action is not allowed is factually wrong. The denial is not caused by a missing permit but by the policy's condition block: the action is allowed only under certain conditions. Because the source IP is outside the permitted ranges, the Allow statement is filtered out and the implicit deny takes effect.
- ✗
The user can access objects because the condition for SecureTransport is met.
Why it's wrong here
The SecureTransport condition is indeed part of the statement, and if the user made the request over HTTPS that condition is true. However, IAM condition blocks apply all provided condition keys with logical AND; every key must match before the Allow is granted. The source IP condition is not met, so the request is denied despite the satisfied SecureTransport condition.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.