SOA-C02 aws:SourceVpce Practice Question
A SysOps administrator needs to restrict access to an Amazon S3 bucket so that only requests from a specific VPC endpoint are allowed. Which policy statement should be added to the bucket policy?
⚠ Common exam trap
A common trap is confusing 'aws:SourceVpc' with 'aws:SourceVpce'. The former restricts to traffic from any resource in the specified VPC, while the latter restricts to traffic specifically from the VPC endpoint.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Condition: { StringEquals: { 'aws:SourceVpce': 'vpce-12345' } }
The condition key 'aws:SourceVpce' is used to restrict access to requests originating from a specific VPC endpoint (identified by its endpoint ID). Option A uses 'aws:SourceVpc', which restricts to an entire VPC, not a specific endpoint. Option B uses 'ec2:Vpc', which is not a valid condition key for S3 bucket policies. Option C uses 'aws:VpcSourceIp', which is not a valid condition key; the correct key for IP-based restrictions is 'aws:SourceIp'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Condition: { StringEquals: { 'aws:SourceVpc': 'vpc-12345' } }
Why it's wrong here
The 'aws:SourceVpc' condition key is a valid global condition that identifies the source VPC of a request, but it is too broad for this requirement: it would allow any request originating from anywhere inside the entire VPC, not just requests that came through the specific VPC endpoint. This includes traffic from other endpoints, from directly addressed resources, or from any workload within that VPC, so it cannot enforce the required endpoint-level restriction.
- ✗
Condition: { StringEquals: { 'ec2:Vpc': 'vpc-12345' } }
Why it's wrong here
The 'ec2:Vpc' condition key is an EC2-specific condition that is used in IAM policies or EC2 resource-level permissions to match resources (like instances or volumes) based on their associated VPC. It is not a valid condition key for S3 bucket policies, and S3 does not evaluate 'ec2:Vpc' when authorizing requests; attempting to use it will simply not restrict the request and can cause the policy to fail to match, leaving access uncontrolled.
- ✗
Condition: { IpAddress: { 'aws:VpcSourceIp': '10.0.0.0/16' } }
Why it's wrong here
The condition key 'aws:VpcSourceIp' does not exist in AWS identity-based or resource-based policy contexts. The valid key for IP-based conditions is 'aws:SourceIp', but that key would reflect the source IP address of the requester (which, over a VPC endpoint, is typically the private IP of the instance) and still would not identify the specific VPC endpoint. Because the key name itself is invalid, AWS will return an error or the condition will never be satisfied, and it does not achieve endpoint-specific restriction.
- ✓
Condition: { StringEquals: { 'aws:SourceVpce': 'vpce-12345' } }
Why this is correct
The condition key 'aws:SourceVpce' is the standard and correct way to restrict an S3 bucket policy to a specific VPC endpoint. When a request is made through an AWS PrivateLink VPC endpoint, this global condition contains the endpoint ID (e.g., 'vpce-12345'), allowing you to write a policy that only grants access to that exact endpoint. This ensures that traffic from the VPC must route through the named endpoint, and direct traffic from instances or other endpoints is denied.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.