IAM policy conditions let you allow or deny access only when specific criteria are met — a source IP range, MFA being present, a specific tag, a time window. They make permissions precise instead of all-or-nothing.

Common condition keys

The exam likes conditions such as aws:SourceIp (restrict by IP), aws:MultiFactorAuthPresent (require MFA), aws:RequestedRegion (restrict Regions), and tag-based conditions. They attach to a policy statement’s Condition block and apply on top of the base allow/deny.

Test yourself

Practice question

You must allow an action ONLY when the request comes from the corporate IP range. What makes this possible in an IAM policy?

  1. A separate IAM user per office
  2. A Condition block using aws:SourceIp
  3. A security group rule
  4. A NACL entry
👉 Click to reveal the answer & explanation

Correct answer: B. An IAM policy Condition with the aws:SourceIp key restricts the permission to specific IP ranges. Separate users (A) don’t enforce IP; security groups (C) and NACLs (D) filter network traffic, not IAM API permissions.

Related topics

IAM roles vs policies · AWS IAM · Permission boundaries

CloudExamPro Premium

Ready to pass the AWS Solutions Architect Associate (SAA-C03)?

Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.

  • ✓  6 full-length practice exams
  • ✓  A detailed explanation for every single question
  • ✓  Realistic, scenario-based questions — not memory dumps
  • ✓  Lifetime access, kept current for 2026

Get the SAA-C03 Practice Exams →or try 25 free questions first

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access