Courseiva
Security and Compliance →hardMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company's security team notices that an IAM user has permissions to terminate EC2 instances but should only be allowed to stop them. The current policy allows ec2:TerminateInstances. What is the most secure way to prevent termination while allowing stop?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a Deny statement for ec2:TerminateInstances with a condition for the user's ARN.

The most secure because adding a Deny statement for ec2:TerminateInstances with a condition for the user's ARN explicitly blocks the termination action, regardless of any other policies that might allow it. Option A is wrong because an SCP affects the entire account, not just the user, and may be too broad. Option B is wrong because simply modifying the policy to include ec2:StopInstances and remove ec2:TerminateInstances does not prevent termination if the user has other policies that grant ec2:TerminateInstances. Option D is wrong because attaching a separate Deny policy is effective but less direct and more complex than adding a Deny in the same policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use an SCP to deny ec2:TerminateInstances for the entire account.

    Why it's wrong here

    An SCP attached at the account or OU level acts as a permission boundary for every principal in that account, not just the offending IAM user. Using it to deny ec2:TerminateInstances would block termination for all users and roles, including legitimate administrative workflows, which violates the principle of least privilege and is far broader than the single-user fix required here.

  • ✗

    Modify the existing policy to include ec2:StopInstances and remove ec2:TerminateInstances.

    Why it's wrong here

    Simply removing ec2:TerminateInstances from the user's identity-based policy does not guarantee the user loses that permission—they could still inherit it from a group policy, a managed policy, or a broad resource-based statement. An explicit Deny statement is more secure because it overrides any Allow from other policies, making it the definitive safeguard against the unwanted action.

  • ✓

    Add a Deny statement for ec2:TerminateInstances with a condition for the user's ARN.

    Why this is correct

    Placing an explicit Deny on ec2:TerminateInstances with a condition key like aws:PrincipalArn set to the user's ARN directly and narrowly blocks only that principal from terminating instances. This Deny overrides any Allow for the action, regardless of other policies, while leaving the user's ability to stop instances intact and preserving permissions for all other IAM principals.

  • ✗

    Attach a separate managed policy that denies ec2:TerminateInstances to the user.

    Why it's wrong here

    A separate managed policy that denies ec2:TerminateInstances could technically work, but it adds a second authorization document that must be attached and maintained. Without a condition scoping it to the user's ARN, such a policy is also more likely to be reused unintentionally, and it is less transparent than editing the user's existing policy to include an explicit Deny statement with the exact principal condition.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.