Courseiva

SCS-C02 Identity and Access Management Practice Question

A security engineer is designing a permissions boundary for an IAM user. Which TWO statements about permissions boundaries are correct?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The effective permissions are the intersection of the identity-based policy and the permissions boundary.

Option C is correct because AWS evaluates a permissions boundary as a filter: the effective permissions for an IAM principal are the intersection of what the identity-based policy allows and what the permissions boundary allows, so an action must be permitted by both to succeed. Option E is correct because a permissions boundary is only a maximum-permissions guardrail; it never grants access by itself, and the principal still needs an identity-based policy (or another applicable policy) that allows the action. Options A and B are wrong because permissions boundaries can be attached to IAM users and IAM roles (including service roles), but not to service-linked roles, which are managed by AWS and do not support permissions boundaries. Option D is wrong because permissions boundaries only limit identity-based permissions and cannot expand or override resource-based policies; resource-based policies are evaluated separately and can grant access independently of the boundary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Permissions boundaries can be applied to service-linked roles.

    Why it's wrong here

    Permissions boundaries attach to IAM users and roles, but service-linked roles are created and managed by the linked service and cannot carry a customer-managed boundary. They would be the right vehicle for capping a custom role's maximum permissions, not for service-linked roles.

  • ✗

    Permissions boundaries can only be applied to IAM users, not roles.

    Why it's wrong here

    Permissions boundaries apply to IAM users and IAM roles alike, so restricting them to users alone misstates the feature. They would be the correct choice when capping the maximum permissions of either a user or a role, including roles assumed by federated identities.

  • ✓

    The effective permissions are the intersection of the identity-based policy and the permissions boundary.

    Why this is correct

    A permissions boundary caps identity-based policies: the principal can only perform actions allowed by both. Effective permissions therefore equal the intersection, so an action permitted by the identity policy but absent from the boundary is denied.

  • ✗

    Permissions boundaries can override resource-based policies.

    Why it's wrong here

    A permissions boundary only caps the identity-based permissions granted to a principal; it never overrides resource-based policies, which are evaluated separately in the request authorisation logic. Boundaries would be the correct control when limiting what an identity policy can grant, not when governing cross-account resource grants.

  • ✓

    A permissions boundary alone does not grant permissions; an identity-based policy is also required.

    Why this is correct

    Permissions boundaries only set a maximum; they never grant access by themselves. An identity-based policy must separately allow the action, and the effective permission is the intersection of the two, so a boundary alone yields no permissions.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.