SCS-C02 Identity and Access Management Practice Question
A company uses AWS Organizations with a service control policy (SCP) that denies all actions except those explicitly listed. A developer in a member account needs to launch an EC2 instance with an IAM role that grants access to an S3 bucket. The SCP currently allows ec2:RunInstances and s3:GetObject but denies iam:PassRole. What is the MOST likely effect?
⚠ Common exam trap
The trap here is thinking that ec2:RunInstances alone is sufficient to launch an instance with a role, forgetting that iam:PassRole is a separate required permission.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The developer cannot launch the instance because the SCP denies iam:PassRole, which is required to associate the role with the instance.
iam:PassRole is mandatory for a principal to associate an IAM role with an EC2 instance. When an SCP denies iam:PassRole, the RunInstances action fails even if ec2:RunInstances is allowed. This prevents unauthorized role escalation. The other options incorrectly assume the launch can succeed or misunderstand the scope of SCPs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The developer can launch the instance, but the instance will not be able to assume the IAM role because iam:PassRole is denied.
Why it's wrong here
iam:PassRole is required for the developer to pass the role to the EC2 instance at launch. If the SCP denies iam:PassRole, the launch itself will fail with an AccessDenied error. The instance cannot be launched without passing the role, so it will not exist to assume the role. This option incorrectly assumes the launch succeeds.
- ✗
The developer can launch the instance, and the instance will use the role's permissions because the SCP only applies to the developer, not the instance.
Why it's wrong here
SCPs apply to all principals in the account, including the developer, and they also affect the permissions available to the instance's role if the role is used within the account. However, the immediate issue is that the developer cannot pass the role to the instance. The instance cannot assume a role that was never attached. This option misunderstands how SCPs and PassRole interact.
- ✗
The developer can launch the instance if they use an existing instance profile instead of passing the role directly.
Why it's wrong here
Using an existing instance profile still requires iam:PassRole for the role contained in that profile. The SCP denies iam:PassRole regardless of whether the role is passed directly or via an instance profile. Therefore, the developer cannot bypass the restriction by using an instance profile; the launch will still fail with an access denied error.
- ✓
The developer cannot launch the instance because the SCP denies iam:PassRole, which is required to associate the role with the instance.
Why this is correct
To launch an EC2 instance with an IAM role, the caller must have iam:PassRole permission for that role. An SCP that denies iam:PassRole blocks this action, so the RunInstances call fails. Even though ec2:RunInstances is allowed, the missing PassRole permission prevents the role association, making the launch unsuccessful. This is the intended security control.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.