SAP-C02 Design for New Solutions Practice Question
Exhibit
Refer to the exhibit.
# IAM policy snippet
{
"Effect": "Allow",
"Action": "ec2:Describe*",
"Resource": "*"
}Refer to the exhibit. An IAM policy allows ec2:Describe* actions on all resources. A developer wants to also allow describing RDS instances. Which action must be added to the policy?
⚠ Common exam trap
Many candidates assume `ec2:Describe*` covers all AWS describe operations across services, but IAM actions are scoped per service namespace (e.g., `ec2:`, `rds:`), and each service has its own set of actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
rds:Describe*
AWS IAM policies use the `rds:Describe*` action to grant permission to describe RDS instances, DB snapshots, DB parameter groups, and other RDS resources. The `ec2:Describe*` action only covers EC2 resources, not RDS resources, so a separate RDS-specific action is required. The wildcard `*` after `Describe` matches all RDS describe operations, including `rds:DescribeDBInstances`.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
rds:List*
Why it's wrong here
RDS instance descriptions use the rds:DescribeDBInstances action, not any rds:List* action; List* covers resource enumeration such as rds:ListTagsForResource. It is tempting because List* sounds analogous to Describe*, but the RDS API simply has no rds:List* action that returns instance details.
- ✗
rds:Get*
Why it's wrong here
rds:Get* covers only Get-type RDS API calls, not the DescribeDBInstances action needed to describe RDS instances. It tempts because Get and Describe both read data, but IAM matches action names literally, so rds:Describe* must be added.
- ✓
rds:Describe*
Why this is correct
Adding `rds:Describe*` grants the specific RDS read permissions the developer needs, satisfying the requirement to describe RDS instances. IAM evaluates actions per service namespace, so EC2's `ec2:Describe*` wildcard never covers RDS API calls; a separate RDS statement is mandatory.
- ✗
ec2:DescribeRdsInstances
Why it's wrong here
DescribeRdsInstances is not a valid EC2 action; RDS instances are described through the rds namespace, so this string matches nothing and grants no permission. It tempts because the existing policy is EC2-scoped, but cross-service resources always require the owning service's action prefix.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.