IAM policy conditions let you allow or deny access only when specific criteria are met — a source IP range, MFA being present, a specific tag, a time window. They make permissions precise instead of all-or-nothing.
Common condition keys
The exam likes conditions such as aws:SourceIp (restrict by IP), aws:MultiFactorAuthPresent (require MFA), aws:RequestedRegion (restrict Regions), and tag-based conditions. They attach to a policy statement’s Condition block and apply on top of the base allow/deny.
Test yourself
You must allow an action ONLY when the request comes from the corporate IP range. What makes this possible in an IAM policy?
- A separate IAM user per office
- A Condition block using aws:SourceIp
- A security group rule
- A NACL entry
👉 Click to reveal the answer & explanation
Correct answer: B. An IAM policy Condition with the aws:SourceIp key restricts the permission to specific IP ranges. Separate users (A) don’t enforce IP; security groups (C) and NACLs (D) filter network traffic, not IAM API permissions.
Related topics
IAM roles vs policies · AWS IAM · Permission boundaries
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first