DVA-C02 Security Practice Question
A developer needs to grant an IAM user the ability to create and manage EC2 instances, but only in the us-east-1 region. Which IAM policy statement should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
{"Effect": "Allow", "Action": "ec2:*", "Resource": "*", "Condition": {"StringEquals": {"ec2:Region": "us-east-1"}}}
The Condition element with ec2:Region restricts the allowed actions to only the us-east-1 region, while allowing all EC2 actions (ec2:*). Option B is incorrect because it only permits Describe actions, not creating or managing instances. Option C is incorrect because although the Resource ARN includes the region, the ec2:* actions do not support resource-level restrictions with region in the ARN in the same way; a Condition is needed. Option D is incorrect because it allows EC2 actions in all regions with no restriction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
{"Effect": "Allow", "Action": "ec2:*", "Resource": "*", "Condition": {"StringEquals": {"ec2:Region": "us-east-1"}}}
Why this is correct
This policy grants full ec2:* permissions but attaches a Condition block that checks the ec2:Region condition key against 'us-east-1'. Because ec2:Region is populated by AWS on every EC2 API call based on the endpoint's region, this condition reliably scopes the allowed actions to that one region regardless of which resource ARN is targeted.
- ✗
{"Effect": "Allow", "Action": "ec2:Describe*", "Resource": "*"}
Why it's wrong here
This statement only permits actions matching the ec2:Describe* wildcard, which covers read-only calls like DescribeInstances and DescribeVolumes. It grants no permission to launch, stop, terminate, or otherwise manage instances, so it fails the 'create and manage' requirement entirely, independent of any region restriction.
- ✗
{"Effect": "Allow", "Action": "ec2:*", "Resource": "arn:aws:ec2:us-east-1:*:*"}
Why it's wrong here
Many EC2 API actions, including RunInstances, do not support resource-level permissions scoped by ARN in the same way S3 or IAM do, and the region segment of an EC2 ARN is not evaluated as an authorization boundary the way a Condition key is — so constraining the Resource ARN to us-east-1 does not actually stop the user from calling EC2 APIs against other regions.
- ✗
{"Effect": "Allow", "Action": "ec2:*", "Resource": "*"}
Why it's wrong here
This statement grants ec2:* on all resources with no Condition element at all, so the user could create and manage EC2 instances in every AWS region, not just us-east-1, which directly violates the region-scoping requirement in the question.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.