DVA-C02 Security Practice Question
A developer needs to allow a user to deploy AWS CloudFormation stacks but restrict the user from creating or modifying IAM resources. Which IAM policy should the developer attach to the user?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"cloudformation:*","Resource":"*"},{"Effect":"Deny","Action":"iam:*","Resource":"*"}]}
It grants full access to CloudFormation actions via an Allow statement while explicitly denying all IAM actions via a Deny statement, ensuring the user can deploy stacks but cannot create or modify IAM resources. Option B is incorrect because it allows all IAM actions, granting excessive permissions. Option C is incorrect because it allows CloudFormation but does not explicitly deny IAM, which could permit IAM actions if other policies allow. Option D is incorrect because it denies all CloudFormation actions, preventing stack deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"cloudformation:*","Resource":"*"},{"Effect":"Deny","Action":"iam:*","Resource":"*"}]}
Why this is correct
This policy combines an Allow on cloudformation:* with an explicit Deny on iam:*. Because an explicit deny always overrides an allow in IAM's evaluation logic, the user can create, update, and delete stacks freely, but any attempt to create, modify, or delete IAM roles, users, or policies — even indirectly through a stack template — is blocked.
- ✗
{"Effect":"Allow","Action":"iam:*","Resource":"*"}
Why it's wrong here
This statement grants unrestricted iam:* permissions and contains no CloudFormation actions at all, so the user would be able to create and modify IAM roles, users, and policies directly, but would have no ability to deploy, update, or delete any CloudFormation stack, which is the opposite of the stated requirement.
- ✗
{"Effect":"Allow","Action":"cloudformation:*","Resource":"*"}
Why it's wrong here
This grants full cloudformation:* access but places no restriction on IAM actions whatsoever. Because CloudFormation stacks can embed AWS::IAM::Role or AWS::IAM::Policy resources, the user could deploy a template that creates or modifies IAM entities indirectly, completely defeating the goal of preventing IAM changes.
- ✗
{"Effect":"Deny","Action":"cloudformation:*","Resource":"*"}
Why it's wrong here
This statement denies every CloudFormation action outright, which technically prevents any IAM changes made through stacks but only because it also prevents the user from deploying, updating, or managing any stack at all — failing the primary requirement of allowing CloudFormation deployments.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.