SAP-C02 Continuous Improvement for Existing Solutions Practice Question
Exhibit
Refer to the exhibit.
Resource: "arn:aws:ec2:us-east-1:123456789012:instance/*"
Condition:
StringEquals:
ec2:InstanceType:
- "t2.micro"
- "t2.small"An IAM policy condition allows launching EC2 instances only if the instance type is t2.micro or t2.small. A developer tries to launch a t2.medium instance. What happens?
⚠ Common exam trap
SAP-C02 often tests the misconception that a condition in an Allow statement acts as a deny; candidates must remember that a failed condition simply means the Allow does not apply, resulting in an implicit deny.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The launch is denied because t2.medium is not in the allowed list.
IAM policies are evaluated with an implicit deny by default; an Allow statement with a condition only grants permissions when the condition is satisfied. Since the condition restricts instance types to t2.micro or t2.small, launching a t2.medium does not match the condition, so the Allow does not apply and the request is denied. No separate Deny statement is needed—the absence of a matching Allow results in denial.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The launch is denied only if the user does not have a separate policy allowing t2.medium.
Why it's wrong here
IAM evaluates all applicable policies together; an explicit Allow for t2.medium in another policy overrides the condition-scoped Allow, so the launch succeeds, not fails. It is tempting because explicit denies do override allows, but a condition restricting one Allow statement is not an explicit Deny, so this misreads the evaluation logic.
- ✗
The launch succeeds because the condition only allows, not denies.
Why it's wrong here
The condition scopes the Allow to t2.micro and t2.small, so a t2.medium request matches no Allow statement and is implicitly denied by default. It is tempting because conditions do filter Allow statements rather than acting as Denies, yet the absence of any matching Allow still yields an implicit deny.
- ✗
The launch succeeds if the user has an additional Allow for t2.medium.
Why it's wrong here
An additional Allow for t2.medium would indeed permit the launch, but the scenario states only the condition-scoped policy exists, so no such Allow is present and the request is implicitly denied. It is tempting because multiple Allow statements do combine, which would be correct had the stem included that second policy.
- ✓
The launch is denied because t2.medium is not in the allowed list.
Why this is correct
The condition key `ec2:InstanceType` evaluates the requested type against the allowed values, and t2.medium matches neither t2.micro nor t2.small. Because IAM denies any request failing a condition in an Allow statement, the RunInstances call is rejected outright. The developer receives an unauthorised operation error, satisfying the stem's allow-list constraint.
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.