Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The application stores sensitive data in an S3 bucket. The security team has mandated that all data in transit to the S3 bucket must be encrypted using TLS. The SysOps administrator configured the application to use HTTPS endpoints for S3. However, a security audit reveals that some requests to S3 are still being sent over HTTP. The administrator checks the VPC Flow Logs and sees that the EC2 instances are communicating with the S3 bucket via a VPC endpoint. The company also uses an S3 bucket policy that allows access only from the VPC endpoint. What is the most likely reason that some requests are sent over HTTP?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The application is not configured to use HTTPS for all S3 requests.

The VPC endpoint for S3 does not automatically encrypt traffic; encryption is handled at the application level. The application must be configured to use HTTPS for all S3 requests. Even though the administrator configured the application to use HTTPS endpoints, some requests may still be sent over HTTP if the application has fallback logic or uses an SDK that defaults to HTTP in certain cases. Option A is incorrect because the VPC endpoint itself does not encrypt traffic; encryption is an application-layer function. Option B is incorrect because VPC endpoints are not configured for HTTP or HTTPS; they use AWS API calls which can be made over either protocol depending on the client. Option C is incorrect because the S3 bucket policy does not require HTTPS; it only restricts access to the VPC endpoint, not the protocol.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The VPC endpoint is not encrypting traffic between the instances and the endpoint.

    Why it's wrong here

    This is incorrect because a VPC endpoint for S3 provides a private network path to S3 over the AWS backbone, but it does not inherently encrypt traffic. Encryption-in-transit to S3 is a function of using the HTTPS endpoint; if the application issues HTTP requests, the data remains plaintext even over the endpoint. Thus the VPC endpoint is not the cause of unencrypted traffic; the application's protocol is.

  • ✗

    The VPC endpoint is configured for HTTP instead of HTTPS.

    Why it's wrong here

    A VPC endpoint is not an HTTP/HTTPS proxy or web server; it is a routing construct (gateway endpoint) or a private IP interface (interface endpoint) that forwards API calls to S3's native service endpoint. There is no property on the VPC endpoint that selects HTTP versus HTTPS — that selection resides entirely in the client application code. Therefore, blaming the endpoint for an HTTP configuration is a category error.

  • ✗

    The S3 bucket policy does not require HTTPS for requests.

    Why it's wrong here

    A bucket policy can deny HTTP requests by adding a condition such as aws:SecureTransport equals false, but without such a policy, S3 will still accept both HTTP and HTTPS requests. The absence of a restrictive policy does not cause the application to make HTTP calls; the client simply defaults to whatever protocol it is coded to use. So this is not the root cause.

  • ✓

    The application is not configured to use HTTPS for all S3 requests.

    Why this is correct

    This is the correct root cause. The application must use HTTPS endpoints when calling S3 (e.g., https://bucket.s3.amazonaws.com) to encrypt data in transit between the EC2 instances and S3. Even when using a VPC endpoint, the application's SDK or code explicitly determines whether requests are signed and sent over TLS. If the code uses HTTP URLs or does not enforce TLS, traffic is sent in plaintext, exposing data on the network.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.