SCS-C02 Infrastructure Security Practice Question
Exhibit
Refer to the exhibit.
```
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "ec2:*",
"Resource": "*"
},
{
"Effect": "Deny",
"Action": "ec2:DeleteVolume",
"Resource": "arn:aws:ec2:us-east-1:123456789012:volume/*",
"Condition": {
"StringNotEquals": {
"ec2:ResourceTag/Environment": "Production"
}
}
}
]
}
```A security engineer is reviewing an IAM policy attached to a user. The policy is intended to allow all EC2 actions except deleting volumes in the Production environment. However, the user reports being able to delete volumes that are tagged with Environment=Production. What is the reason for this behavior?
⚠ Common exam trap
A common mix-up: candidates confuse StringNotEquals with StringEquals, assuming that StringNotEquals will deny the specified tag value, when in fact it denies all other values, allowing the intended target to pass through.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The condition in the Deny statement uses StringNotEquals, which denies deletion for non-Production volumes, not Production volumes.
The Deny statement uses the StringNotEquals condition operator with ec2:ResourceTag/Environment=Production. This means the Deny applies when the tag value is NOT equal to Production, so it denies deletion for non-Production volumes but allows deletion for Production volumes. To deny deletion of Production volumes, the policy should use StringEquals instead of StringNotEquals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy is not attached to the correct IAM entity.
Why it's wrong here
This is not the issue because the scenario explicitly states the policy is attached to the IAM user, so the policy is in fact applied to that user's principal. IAM policies are associated with users, groups, or roles, but once attached to the user, the entity requirement is satisfied. The flaw is not attachment, but the behavior of the Deny condition.
- ✗
The Deny statement should use iam:ResourceTag instead of ec2:ResourceTag.
Why it's wrong here
The condition key prefix must match the service whose resource you are evaluating: EC2 volumes expose tags through ec2:ResourceTag, not iam:ResourceTag. Using iam:ResourceTag would make the Deny statement match against a key that does not exist for an EC2 volume, so the condition would not evaluate to true and the deny would not block the action. Therefore, the prefix is correct as written; the real defect is the StringNotEquals operator.
- ✓
The condition in the Deny statement uses StringNotEquals, which denies deletion for non-Production volumes, not Production volumes.
Why this is correct
The StringNotEquals operator evaluates to true when the volume's tag value is anything other than Production, so the Deny applies only to non-Production volumes. Production-tagged volumes fail the negative condition and are therefore allowed by the Deny statement to be deleted. If the goal is to protect Production volumes from deletion, the policy should use StringEquals with the value Production so that only matching volumes are denied.
- ✗
The Allow statement uses a wildcard for the action, which overrides the Deny statement.
Why it's wrong here
In IAM policy evaluation, an explicit Deny always overrides every Allow, regardless of whether the Allow action uses a wildcard or specifies a specific action. The wildcard only broadens which actions are permitted under the Allow, but it cannot supersede the Deny statement. Thus the Allow statement does not nullify the Deny; the Deny would still block any action that matches its action and condition.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.