Courseiva
Security →easyMultiple Choice

DVA-C02 Security Practice Question

A developer needs to allow an IAM user to stop and start EC2 instances but not terminate them. Which IAM policy effect and action combination should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allow ec2:StopInstances and ec2:StartInstances

It explicitly allows ec2:StopInstances and ec2:StartInstances, which grants the needed permissions without allowing ec2:TerminateInstances. Option B is incorrect because it includes ec2:TerminateInstances, which would allow termination, contrary to the requirement. Option C is incomplete: although it denies ec2:TerminateInstances, it does not allow ec2:StopInstances or ec2:StartInstances, so the user would not have the required start/stop permissions. Option D is incorrect because it allows ec2:TerminateInstances.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Allow ec2:StopInstances and ec2:StartInstances

    Why this is correct

    Granting only ec2:StartInstances and ec2:StopInstances gives the IAM user exactly the actions needed to power instances on and off while omitting ec2:TerminateInstances entirely, so any attempt to terminate an instance is implicitly denied by IAM's default-deny behavior, satisfying the requirement precisely.

  • ✗

    Allow ec2:StopInstances, ec2:StartInstances, and ec2:TerminateInstances

    Why it's wrong here

    Including ec2:TerminateInstances alongside the start and stop actions grants the exact permission the requirement explicitly forbids; even though stop and start are correctly allowed, the presence of terminate permission means a user could permanently destroy the instance and any attached instance-store data, violating the stated constraint.

  • ✗

    Deny ec2:TerminateInstances

    Why it's wrong here

    An explicit Deny statement for ec2:TerminateInstances alone does not grant any permissions at all; without a corresponding Allow statement for ec2:StartInstances and ec2:StopInstances, the user would still be blocked from stopping or starting instances by IAM's implicit-deny default, since Deny only removes access and never grants it.

  • ✗

    Allow ec2:StartInstances and ec2:TerminateInstances

    Why it's wrong here

    This combination omits ec2:StopInstances, so the user could not gracefully stop a running instance, and it also grants ec2:TerminateInstances, which permanently deletes the instance; it therefore both under-provisions the required capability and over-grants a destructive one in the same statement.

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.