Courseiva
Design for New Solutions →easyMultiple Choice

SAP-C02 Design for New Solutions Practice Question

Exhibit

Refer to the exhibit.
# IAM policy snippet
{
    "Effect": "Allow",
    "Action": "ec2:Describe*",
    "Resource": "*"
}

Refer to the exhibit. An IAM policy allows ec2:Describe* actions on all resources. A developer wants to also allow describing RDS instances. Which action must be added to the policy?

⚠ Common exam trap

Many candidates assume `ec2:Describe*` covers all AWS describe operations across services, but IAM actions are scoped per service namespace (e.g., `ec2:`, `rds:`), and each service has its own set of actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

rds:Describe*

AWS IAM policies use the `rds:Describe*` action to grant permission to describe RDS instances, DB snapshots, DB parameter groups, and other RDS resources. The `ec2:Describe*` action only covers EC2 resources, not RDS resources, so a separate RDS-specific action is required. The wildcard `*` after `Describe` matches all RDS describe operations, including `rds:DescribeDBInstances`.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    rds:List*

    Why it's wrong here

    RDS instance descriptions use the rds:DescribeDBInstances action, not any rds:List* action; List* covers resource enumeration such as rds:ListTagsForResource. It is tempting because List* sounds analogous to Describe*, but the RDS API simply has no rds:List* action that returns instance details.

  • ✗

    rds:Get*

    Why it's wrong here

    rds:Get* covers only Get-type RDS API calls, not the DescribeDBInstances action needed to describe RDS instances. It tempts because Get and Describe both read data, but IAM matches action names literally, so rds:Describe* must be added.

  • ✓

    rds:Describe*

    Why this is correct

    Adding `rds:Describe*` grants the specific RDS read permissions the developer needs, satisfying the requirement to describe RDS instances. IAM evaluates actions per service namespace, so EC2's `ec2:Describe*` wildcard never covers RDS API calls; a separate RDS statement is mandatory.

  • ✗

    ec2:DescribeRdsInstances

    Why it's wrong here

    DescribeRdsInstances is not a valid EC2 action; RDS instances are described through the rds namespace, so this string matches nothing and grants no permission. It tempts because the existing policy is EC2-scoped, but cross-service resources always require the owning service's action prefix.

About these practice questions

Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.