Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

Exhibit

Refer to the exhibit.

Error: User: arn:aws:iam::123456789012:user/Developer is not authorized to perform: ec2:RunInstances on resource: arn:aws:ec2:us-east-1:123456789012:instance/* with an explicit deny in a service control policy

A developer receives the above error when trying to launch an EC2 instance. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An SCP at the organizational level denies ec2:RunInstances

The error message explicitly mentions a service control policy (SCP) that denies the action, indicating that an SCP at the organizational level is blocking the ec2:RunInstances action. Option C is therefore correct. Option A is incorrect because instance limit errors show a message about reaching the maximum number of instances, not an SCP denial. Option B is incorrect because VPC restrictions typically produce errors related to network constraints, not an explicit SCP reference. Option D is incorrect because an IAM policy denial would result in an 'UnauthorizedOperation' error, not one mentioning SCP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The account has reached its EC2 instance limit

    Why it's wrong here

    An EC2 instance limit error typically manifests as "InstanceLimitExceeded" or "You have requested more instances than your current instance limit allows." The error described in the question, however, indicates an explicit denial due to a Service Control Policy (SCP), which is a distinct authorization failure, not a resource quota issue. Resource limits prevent new resource creation due to capacity, whereas SCPs prevent actions based on defined organizational policies.

  • ✗

    The developer is trying to launch the instance in a restricted VPC

    Why it's wrong here

    Errors related to VPC restrictions, such as network ACLs, security groups, or subnet availability, typically manifest as "InsufficientFreeAddressesInSubnet," "SecurityGroupLimitExceeded," or "UnauthorizedOperation" with a specific context about network components. The error in the question explicitly points to an "ec2:RunInstances" action being denied by an SCP, indicating a policy-level restriction on the action itself, independent of the VPC configuration.

  • ✓

    An SCP at the organizational level denies ec2:RunInstances

    Why this is correct

    Service Control Policies (SCPs) in AWS Organizations are designed to set maximum available permissions for all IAM entities within affected accounts. An explicit deny statement within an SCP overrides any allow statements in IAM policies, effectively preventing the "ec2:RunInstances" action from being performed, even if the user's IAM policy explicitly allows it. The error message directly indicating an explicit deny by an SCP precisely matches this behavior.

  • ✗

    The developer's IAM policy does not allow ec2:RunInstances

    Why it's wrong here

    If the developer's IAM policy simply did not allow "ec2:RunInstances," the error message would typically state "User is not authorized to perform this operation" or "Access Denied" without specifically mentioning an explicit deny from a Service Control Policy. An explicit deny in an SCP takes precedence over any allow statements in an IAM policy, meaning even if the IAM policy *did* allow the action, the SCP's deny would still block it, and the error message would reflect the SCP.

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.