passdrill
AWS SAA-C03 · IAM & Security · Card 024/024 easy

A security team wants an S3 bucket policy with two statements: one that denies any request not made over HTTPS, and a separate one that denies any request originating outside the company's known corporate IP range, regardless of which IAM identity makes the request. Which condition keys should these two statements use, respectively?

  1. aws:MultiFactorAuthPresent for the HTTPS requirement, and aws:PrincipalOrgID for the IP-range requirement
  2. aws:SecureTransport for the HTTPS requirement, and aws:SourceIp for the IP-range requirement
  3. aws:SourceIp for the HTTPS requirement, and aws:SecureTransport for the IP-range requirement
  4. aws:CurrentTime for the HTTPS requirement, and aws:UserAgent for the IP-range requirement
Next card → Shuffle