Courseiva
Design Solutions for Organizational ComplexityhardMultiple ChoiceObjective-mapped

How SCPs Restrict EC2 Instance Types Without Affecting Root User

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Action": "ec2:RunInstances",
      "Resource": "arn:aws:ec2:*:*:instance/*",
      "Condition": {
        "StringNotEquals": {
          "ec2:InstanceType": [
            "t3.micro",
            "t3.small"
          ]
        }
      }
    }
  ]
}

Refer to the exhibit. A company applies this SCP to all accounts in an AWS Organization. What is the effect of this policy?

Quick Answer

The correct answer is that the SCP denies launching EC2 instances that are not t3.micro or t3.small for IAM users and roles, but it does not affect the root user. This is because SCPs use a Deny effect with a condition key like ec2:InstanceType, which blocks any RunInstances action unless the type matches the allowed values, yet SCPs inherently cannot restrict the root user in the management account of an AWS Organization. On the AWS Certified Solutions Architect Professional SAP-C02 exam, this scenario tests your understanding that SCPs act as a centralized permission guardrail for all accounts, but the root user in the management account remains exempt—a common trap where candidates assume SCPs apply universally. Remember the memory tip: “SCPs stop the staff, not the superuser,” meaning they restrict IAM users and roles but never the root user in the management account.

⚠ Common exam trap

The trap here is that candidates often forget that SCPs do not apply to the root user of the management account, leading them to incorrectly assume the policy denies all users including root.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Denies launching instances that are not t3.micro or t3.small for IAM users and roles, but not root.

The SCP uses a Deny effect with a condition that denies any EC2:RunInstances action unless the instance type is t3.micro or t3.small. However, SCPs do not affect the root user (the management account's root user) because SCPs cannot restrict the root user in the management account. Therefore, the policy denies launching non-compliant instance types for IAM users and roles, but not for the root user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Allows only t3.micro and t3.small instances to be launched.

    Why it's wrong here

    The SCP denies non-allowed types, but the root user is exempt.

  • Denies launching instances that are not t3.micro or t3.small for IAM users and roles, but not root.

    Why this is correct

    SCPs apply to IAM users and roles, not to root user.

  • Has no effect because SCPs cannot deny actions.

    Why it's wrong here

    SCPs can deny actions.

  • Denies launching any instance except t3.micro and t3.small for all users including root.

    Why it's wrong here

    SCPs do not apply to the root user.

About these practice questions

This SAP-C02 question is part of Courseiva's 1,660-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SAP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses AWS Organizations with multiple accounts. The central IT team wants to restrict the use of specific EC2 instance types across all accounts to control costs. Which approach should the team use?

easy
  • A.Use AWS Budgets to send alerts when costs exceed a threshold.
  • B.Configure Amazon CloudWatch Events to detect launches and terminate instances.
  • C.Attach an IAM policy to each account's root user to deny the ec2:RunInstances action for certain instance types.
  • D.Create a service control policy (SCP) that denies the ec2:RunInstances action for prohibited instance types and apply it to the organization.

Why D: Service control policies (SCPs) are the correct mechanism to centrally restrict permissions across all accounts in an AWS Organization. By creating an SCP that denies the ec2:RunInstances action for specific instance types and applying it to the organization (or relevant OUs), the central IT team can enforce this restriction globally, preventing any IAM principal in any account from launching prohibited instance types, regardless of their IAM permissions.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.