Courseiva

SCS-C02 Management and Security Governance Practice Question

A security engineer is reviewing the following IAM policy attached to a role. Which TWO actions are allowed by this policy? (Choose two.)

```json

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [

"s3:ListBucket", "s3:GetObject"

],
            "Resource": "*"
        }
    ]
}

```

⚠ Common exam trap

SCS-C02 often tests the principle of least privilege and implicit deny — candidates may incorrectly assume that unrelated actions like ec2:TerminateInstances are allowed because the policy uses Resource: "*", confusing resource scope with action scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

s3:ListBucket

Option A (s3:ListBucket) is correct because the policy's Action list explicitly includes "s3:ListBucket" with Effect Allow and Resource "*", so listing any S3 bucket is permitted. Option E (s3:GetObject) is correct because "s3:GetObject" is also explicitly listed in the same Allow statement, granting read access to objects across all resources. The unmarked options do not belong because the policy only allows the two S3 actions named; ec2:TerminateInstances, iam:CreateUser, and kms:Decrypt are not present in the Action list, and IAM policies are deny-by-default for any action not explicitly allowed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    s3:ListBucket

    Why this is correct

    The policy includes an explicit Allow statement for s3:ListBucket on the bucket resource, so this action is permitted. IAM defaults to deny only for actions not covered by any applicable Allow, and because no explicit or resource-based Deny applies to this principal for that bucket, the ListBucket call is authorized. The permission is scoped to the bucket ARN, not individual objects, which matches the resource type required by the ListBucket API.

  • ✗

    ec2:TerminateInstances

    Why it's wrong here

    ec2:TerminateInstances is an Amazon EC2 control-plane action that nothing in this policy references; there is no ec2:* or ec2:TerminateInstances Allow statement. Because IAM uses an implicit deny as the default, the absence of an applicable Allow means the action is not permitted. Even if the user owns the instance, IAM requires a separate permission grant for the terminate call, so this request would be denied.

  • ✗

    iam:CreateUser

    Why it's wrong here

    iam:CreateUser is a management-plane IAM action that can never be satisfied by S3 service permissions; the policy here only grants S3 read operations. No statement lists iam:CreateUser or iam:*, so the request is denied by default. Additionally, creating an IAM user has no relationship to the S3 bucket ARNs referenced in this policy, so no resource element in the policy can match this request.

  • ✗

    kms:Decrypt

    Why it's wrong here

    kms:Decrypt is a KMS API action, and the policy contains no kms:* or kms:Decrypt statement. This matters because an SSE-KMS encrypted object downloaded via s3:GetObject still requires the caller to be authorized in both the KMS key policy and their IAM policy to decrypt the data. Without an explicit kms:Decrypt Allow, any decryption attempt returns an AccessDenied error even though the S3 GET itself may be permitted.

  • ✓

    s3:GetObject

    Why this is correct

    s3:GetObject is explicitly allowed by a statement granting read access to the object ARN, typically expressed as arn:aws:s3:::bucket/*, so downloading an object is authorized. This data-plane permission is the counterpart to s3:ListBucket: the list action lets the caller discover what objects exist, while GetObject restricts the request to retrieving a specific object's contents. As long as no explicit Deny overrides this Allow, the action succeeds under this policy.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.