Courseiva

SCS-C02 Identity and Access Management Practice Question

A financial services company runs a production AWS account. A security engineer must ensure that IAM users cannot disable AWS CloudTrail logging in any region. The engineer attaches a permissions boundary to every IAM user. Which permissions boundary policy statement BEST enforces this requirement?

⚠ Common exam trap

The trap here is assuming that an Allow statement with a restrictive condition is equivalent to a Deny, when only an explicit Deny in a permissions boundary can guarantee the action is blocked.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Deny statement for cloudtrail:StopLogging with no conditions, plus an Allow statement for all other actions the users need.

A permissions boundary defines the maximum permissions an identity can have, and an explicit Deny within it cannot be overridden by identity-based policies. Combining a Deny for cloudtrail:StopLogging with Allow for needed actions prevents any user from disabling logging while preserving normal access. Conditional or tag-scoped statements leave gaps that allow the prohibited action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An Allow statement for cloudtrail:StopLogging with a condition that the request originates from the corporate CIDR range.

    Why it's wrong here

    An Allow statement for cloudtrail:StopLogging, even with a source IP condition, would grant the ability to stop logging when requests come from the corporate network. A permissions boundary must restrict, not grant, privileged actions. This policy would permit exactly the action the company wants to prevent, so it fails the requirement.

  • ✓

    A Deny statement for cloudtrail:StopLogging with no conditions, plus an Allow statement for all other actions the users need.

    Why this is correct

    A permissions boundary with an explicit Deny for cloudtrail:StopLogging and Allow for required actions ensures no identity-based policy can override the deny. The boundary caps maximum permissions, so even if an administrator later attaches a broad policy, the deny remains effective. This directly enforces the requirement without blocking unrelated operations.

  • ✗

    A Deny statement for cloudtrail:StopLogging with a condition that aws:PrincipalTag/role equals 'security-auditor'.

    Why it's wrong here

    Conditioning the deny on a principal tag limits the restriction to only principals carrying that tag. IAM users without the tag would still be able to stop logging. A permissions boundary must apply to all users it is attached to, so a tag-scoped deny does not provide the blanket protection the scenario requires.

  • ✗

    An Allow statement for cloudtrail:* with a condition that aws:RequestedRegion is not the production region.

    Why it's wrong here

    Allowing cloudtrail:* in non-production regions does not prevent StopLogging in the production region. The condition only limits where the action is allowed, not where it is denied. Since CloudTrail logging can be disabled in any region, this boundary leaves the production region unprotected and fails the stated goal.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.