DOP-C02 Configuration Management and IaC Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ec2:DescribeInstances",
"ssm:GetParameter"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"ec2:RunInstances"
],
"Resource": "arn:aws:ec2:us-east-1:123456789012:instance/*",
"Condition": {
"StringEquals": {
"ec2:InstanceType": "t2.micro"
}
}
}
]
}A DevOps team is using this IAM policy to allow a CI/CD pipeline to launch EC2 instances and retrieve parameters. However, the pipeline is failing with an 'AccessDenied' error when trying to create an instance. The pipeline uses a role with this policy attached. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy does not grant permissions on additional resources required for RunInstances, such as images and network interfaces.
The IAM policy likely only grants permissions on the 'ec2:RunInstances' action for the EC2 instance resource (arn:aws:ec2:region:account:instance/*), but creating an EC2 instance also requires permissions on other resources such as Amazon Machine Images (AMI), security groups, network interfaces, subnets, etc. Without explicit permissions on these additional resources, the RunInstances call fails with AccessDenied. Option A is incorrect because the condition syntax does not cause an AccessDenied; it would simply not match if poorly formatted. Option B is incorrect because the ssm:GetParameter action is allowed by the policy if it includes a resource specification, but the failure is on RunInstances, not SSM. Option D is incorrect because DescribeInstances does not require a Resource specification in the policy; the policy syntax is valid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The condition StringEquals on InstanceType is incorrectly formatted.
Why it's wrong here
StringEquals is valid for InstanceType, so the condition's syntax is not the fault. This condition type is genuinely used to restrict launches to specific instance families, making it a plausible culprit when a policy denies an unexpected type. The failure lies elsewhere in the policy's action or resource statements.
- ✗
The pipeline does not have permission to call ssm:GetParameter because the resource is not specified.
Why it's wrong here
The stem reports AccessDenied on instance creation, not on parameter retrieval, so ssm:GetParameter permissions are irrelevant here. Specifying a parameter ARN resource is required for that separate action, and would matter if the pipeline were failing while reading configuration values rather than launching EC2 instances.
- ✓
The policy does not grant permissions on additional resources required for RunInstances, such as images and network interfaces.
Why this is correct
RunInstances requires permissions on dependent resources beyond the instance itself: AMIs, network interfaces, volumes, key pairs and subnets. The policy grants only the instance action, so EC2 authorisation fails when it evaluates those referenced resources, producing AccessDenied. This satisfies the stem's constraint that the pipeline role lacks the necessary dependent-resource permissions.
- ✗
The policy must include a 'Resource' for the 'ec2:DescribeInstances' action to be valid.
Why it's wrong here
ec2:DescribeInstances does not require a Resource element; omitting it or using a wildcard is accepted, so this cannot cause the launch failure. Resource is mandatory only for actions that operate on identifiable objects, such as ec2:RunInstances with a specified AMI or subnet ARN.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.