A company has an S3 bucket policy as shown. A developer tries to upload an object using the AWS CLI without the --no-verify-ssl flag. What will happen?
The bucket policy allows s3:PutObject only when the request is made over a secure transport, as captured by the aws:SecureTransport condition key. The AWS CLI uses the HTTPS endpoint by default, so the request's SecureTransport value is true and the Allow branch applies. Consequently the upload is authorized and completes successfully.
Why this answer
The bucket policy denies requests that do not use secure transport (HTTP) but allows HTTPS requests. The AWS CLI uses HTTPS by default, and since the developer did not use --no-verify-ssl, the request is made over HTTPS. Therefore, the upload succeeds.
Option D is correct. Option A is incorrect because the CLI uses HTTPS, not HTTP. Option B is incorrect because the policy does not deny all s3:* actions; it only denies requests over HTTP.
Option C is incorrect because the policy requires HTTPS, and the CLI complies, so the upload does not fail.