Courseiva

SCS-C02 Identity and Access Management Practice Question

A security engineer is designing a permissions boundary for an IAM role used by an EC2 instance. The role must be able to read from an S3 bucket (my-bucket) and write to CloudWatch Logs. Which THREE conditions must be met for the role to have effective permissions? (Choose THREE.)

⚠ Common exam trap

SCS-C02 often tests the misconception that a permissions boundary grants permissions, when in fact it only limits them — candidates incorrectly select the boundary as sufficient on its own.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The effective permissions are the intersection of the boundary and identity-based policies.

Option B is correct because AWS evaluates a permissions boundary as a filter: the role's effective permissions are the intersection of what the identity-based policy grants and what the boundary allows, so an action must be permitted by both. Option C is correct because the identity-based policy attached to the role is the primary grant of permissions; without it allowing s3:GetObject on my-bucket and logs:CreateLogStream/logs:PutLogEvents, the role has no permissions regardless of the boundary. Option D is correct because the permissions boundary must also allow those same required actions, since any action not permitted by the boundary is denied even if the identity-based policy allows it. Option A is not required for effective permissions because an instance profile is merely the container that delivers a role's temporary credentials to EC2, not a condition that grants or restricts the role's permissions. Option E is not required because a bucket policy is only needed when cross-account access or explicit resource-based grants are involved; for same-account access, the identity-based policy plus boundary is sufficient.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The EC2 instance must have an instance profile attached.

    Why it's wrong here

    An instance profile is the container that carries the IAM role to the EC2 instance via the EC2 Instance Metadata Service (IMDS), and it is required for the instance to assume the role and receive temporary credentials. However, the instance profile itself does not grant any permissions or act as a condition for effective permissions; it is merely a transport mechanism. The question asks what must be true for the permissions boundary to take effect, and the presence of the instance profile is a prerequisite for using the role, not a determinant of the boundary's effect.

  • ✓

    The effective permissions are the intersection of the boundary and identity-based policies.

    Why this is correct

    Effective permissions for any principal are always the intersection of all applicable policies: the permissions boundary acts as a ceiling, and the identity-based policy (e.g., attached to the role) acts as the grant. The IAM engine evaluates both, and an action is permitted only if it is allowed by the identity-based policy, not denied by the boundary, and not denied by any other policy (like a service control policy or resource policy). This intersection model is the fundamental logic of IAM permissions boundaries: the boundary limits the maximum permissions, but the identity policy must still explicitly grant the action within that limit.

  • ✓

    The identity-based policy attached to the role must allow the required actions.

    Why this is correct

    The identity-based policy attached to the role is the primary grant of permissions; permissions boundaries do not grant any permissions themselves, they only restrict what the identity policy can allow. For an action to be permitted, the role's identity policy must explicitly allow that action, and that allow must fall within the boundary. Without an identity policy allowing the required action, the effective permission is denied even if the boundary permits it.

  • ✓

    The permissions boundary policy must allow the required actions.

    Why this is correct

    The permissions boundary policy defines the maximum permissions that the role can have; any action not allowed by the boundary is implicitly denied, even if the identity-based policy explicitly allows it. The boundary policy must allow the required actions because it acts as an upper limit — it cannot grant permissions on its own but it must not prohibit the action. In other words, the boundary is a filter that only permits actions that are both in the boundary and in the identity policy.

  • ✗

    The S3 bucket policy must explicitly allow the role.

    Why it's wrong here

    An S3 bucket policy is a resource-based policy, and while it can grant cross-account access or explicitly deny access, it is not required for the role's identity-based permissions to be effective within the same account. If the role has an identity-based policy that allows the required S3 actions and the permissions boundary also allows them, the role can access the bucket as long as the bucket policy does not explicitly deny the access. Resource-based policies are evaluated in addition to identity-based policies, but unless the bucket policy explicitly denies or the bucket is in a different account, it is not a mandatory element for the boundary's effect.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.