Courseiva

SCS-C02 Identity and Access Management Practice Question

Which FOUR are valid ways to restrict access to an S3 bucket using IAM policies? (Choose 4.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Requiring server-side encryption using the 's3:x-amz-server-side-encryption' condition key

Options A, B, C, and E are all valid ways to restrict access to an S3 bucket using IAM policies. A: The 's3:x-amz-server-side-encryption' condition key can enforce server-side encryption in IAM policies. B: The 'aws:PrincipalOrgID' global condition key can be used in IAM identity-based policies to restrict access to principals from a specific AWS Organization. C: The 'aws:SourceVpc' condition key restricts requests to those originating from a specific VPC. E: The 'aws:SourceIp' condition key restricts access to specific IP addresses. Option D is incorrect because 's3:ResourceAccount' checks the account ID of the resource, not a specific bucket; bucket-specific restriction is done via the Resource element.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Requiring server-side encryption using the 's3:x-amz-server-side-encryption' condition key

    Why this is correct

    Requiring server-side encryption via the 's3:x-amz-server-side-encryption' condition key is a valid access restriction because it makes the presence and value of the x-amz-server-side-encryption header a precondition for the S3 operation. For example, you can require that the header equals AES256 or aws:kms, which denies requests that do not carry an encryption header even if the principal otherwise has s3:PutObject permission. This condition key is evaluated per request, giving you fine-grained, attribute-based control that enforces encryption compliance on all uploads.

  • ✓

    Using the 'aws:PrincipalOrgID' condition key

    Why this is correct

    Using the 'aws:PrincipalOrgID' condition key is a valid organizational boundary control because it restricts access to principals whose AWS account is a member of a specified organization. The condition key uses the organization ID (o-xxxxxx) and is evaluated globally across AWS services, so it works even for cross-account access as long as member accounts are in the same organization. This is especially useful when you want to allow access only to accounts managed by your central governance structure and automatically include any new sub-accounts added to that org.

  • ✓

    Restricting access to a specific VPC using the 'aws:SourceVpc' condition key

    Why this is correct

    Restricting access to a specific VPC with the 'aws:SourceVpc' condition key is valid because it examines the VPC ID from which the request originates, but it only works when a VPC endpoint is configured for S3. When traffic flows through a gateway endpoint or interface endpoint, the source VPC is recorded and evaluated; otherwise, the condition is not met. By combining this condition with the bucket policy, you can reject all requests coming from outside the selected VPC, effectively hiding the bucket from the public internet and other VPCs.

  • ✗

    Using the 's3:ResourceAccount' condition key to restrict access to a specific bucket

    Why it's wrong here

    Using the 's3:ResourceAccount' condition key is incorrect for restricting access to a specific bucket because this key compares the AWS account ID that owns the resource — not the bucket name. A single AWS account may contain many buckets, so the condition only verifies that the bucket belongs to the specified account, which could be all buckets in that account. To isolate one bucket, you must use the bucket ARN in the Resource element of the policy statement, such as arn:aws:s3:::my-bucket, rather than relying on the ResourceAccount condition.

  • ✓

    Limiting access to specific IP addresses using the 'aws:SourceIp' condition key

    Why this is correct

    Limiting access to specific IP addresses with the 'aws:SourceIp' condition key is a valid request-origin restriction because it checks the source IP address from which the API request was made. The condition accepts IPv4 or IPv6 addresses and CIDR blocks, allowing you to whitelist corporate office ranges or other trusted networks while denying all other sources. Be aware that for requests received via a VPC endpoint, the source IP is the endpoint's private IP, so you may need to combine this with 'aws:SourceVpc' if the original client IP is required for the policy decision.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.