SCS-C02 Identity and Access Management Practice Question
A financial services company runs a production AWS account. A security engineer must ensure that IAM users cannot disable AWS CloudTrail logging in any region. The engineer attaches a permissions boundary to every IAM user. Which permissions boundary policy statement BEST enforces this requirement?
⚠ Common exam trap
The trap here is assuming that an Allow statement with a restrictive condition is equivalent to a Deny, when only an explicit Deny in a permissions boundary can guarantee the action is blocked.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Deny statement for cloudtrail:StopLogging with no conditions, plus an Allow statement for all other actions the users need.
A permissions boundary defines the maximum permissions an identity can have, and an explicit Deny within it cannot be overridden by identity-based policies. Combining a Deny for cloudtrail:StopLogging with Allow for needed actions prevents any user from disabling logging while preserving normal access. Conditional or tag-scoped statements leave gaps that allow the prohibited action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An Allow statement for cloudtrail:StopLogging with a condition that the request originates from the corporate CIDR range.
Why it's wrong here
An Allow statement for cloudtrail:StopLogging, even with a source IP condition, would grant the ability to stop logging when requests come from the corporate network. A permissions boundary must restrict, not grant, privileged actions. This policy would permit exactly the action the company wants to prevent, so it fails the requirement.
- ✓
A Deny statement for cloudtrail:StopLogging with no conditions, plus an Allow statement for all other actions the users need.
Why this is correct
A permissions boundary with an explicit Deny for cloudtrail:StopLogging and Allow for required actions ensures no identity-based policy can override the deny. The boundary caps maximum permissions, so even if an administrator later attaches a broad policy, the deny remains effective. This directly enforces the requirement without blocking unrelated operations.
- ✗
A Deny statement for cloudtrail:StopLogging with a condition that aws:PrincipalTag/role equals 'security-auditor'.
Why it's wrong here
Conditioning the deny on a principal tag limits the restriction to only principals carrying that tag. IAM users without the tag would still be able to stop logging. A permissions boundary must apply to all users it is attached to, so a tag-scoped deny does not provide the blanket protection the scenario requires.
- ✗
An Allow statement for cloudtrail:* with a condition that aws:RequestedRegion is not the production region.
Why it's wrong here
Allowing cloudtrail:* in non-production regions does not prevent StopLogging in the production region. The condition only limits where the action is allowed, not where it is denied. Since CloudTrail logging can be disabled in any region, this boundary leaves the production region unprotected and fails the stated goal.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.