A company has the following S3 bucket policy attached to a bucket named 'example-bucket'. A user is unable to download an object from the bucket using an HTTP URL (not HTTPS). What is the cause?
The Deny statement uses Action 's3:*' with a condition checked via aws:SecureTransport set to false, so any S3 API request sent over HTTP instead of HTTPS is denied. In IAM policy evaluation, an explicit Deny always overrides any Allow, meaning the earlier Allow for GetObject does not help when the request is not encrypted. This is exactly why non-HTTPS access is blocked for all S3 operations.
Why this answer
The bucket policy contains a Deny statement that applies to all s3:* actions when the request does not use HTTPS (SecureTransport is false). Even though there is an Allow statement for GetObject to everyone, the explicit Deny overrides the Allow. Option A is incorrect because the issue is not about anonymous users; the Deny affects all requests.
Option C is incorrect because the policy does not mention server-side encryption. Option D is incorrect because the Deny statement applies to all S3 actions, not just PutObject.