SCS-C02 Management and Security Governance Practice Question
A security engineer is reviewing the following IAM policy attached to a role. Which TWO actions are allowed by this policy? (Choose two.)
```json
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:ListBucket", "s3:GetObject"
],
"Resource": "*"
}
]
}```
⚠ Common exam trap
SCS-C02 often tests the principle of least privilege and implicit deny — candidates may incorrectly assume that unrelated actions like ec2:TerminateInstances are allowed because the policy uses Resource: "*", confusing resource scope with action scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
s3:ListBucket
Option A (s3:ListBucket) is correct because the policy's Action list explicitly includes "s3:ListBucket" with Effect Allow and Resource "*", so listing any S3 bucket is permitted. Option E (s3:GetObject) is correct because "s3:GetObject" is also explicitly listed in the same Allow statement, granting read access to objects across all resources. The unmarked options do not belong because the policy only allows the two S3 actions named; ec2:TerminateInstances, iam:CreateUser, and kms:Decrypt are not present in the Action list, and IAM policies are deny-by-default for any action not explicitly allowed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
s3:ListBucket
Why this is correct
The policy includes an explicit Allow statement for s3:ListBucket on the bucket resource, so this action is permitted. IAM defaults to deny only for actions not covered by any applicable Allow, and because no explicit or resource-based Deny applies to this principal for that bucket, the ListBucket call is authorized. The permission is scoped to the bucket ARN, not individual objects, which matches the resource type required by the ListBucket API.
- ✗
ec2:TerminateInstances
Why it's wrong here
ec2:TerminateInstances is an Amazon EC2 control-plane action that nothing in this policy references; there is no ec2:* or ec2:TerminateInstances Allow statement. Because IAM uses an implicit deny as the default, the absence of an applicable Allow means the action is not permitted. Even if the user owns the instance, IAM requires a separate permission grant for the terminate call, so this request would be denied.
- ✗
iam:CreateUser
Why it's wrong here
iam:CreateUser is a management-plane IAM action that can never be satisfied by S3 service permissions; the policy here only grants S3 read operations. No statement lists iam:CreateUser or iam:*, so the request is denied by default. Additionally, creating an IAM user has no relationship to the S3 bucket ARNs referenced in this policy, so no resource element in the policy can match this request.
- ✗
kms:Decrypt
Why it's wrong here
kms:Decrypt is a KMS API action, and the policy contains no kms:* or kms:Decrypt statement. This matters because an SSE-KMS encrypted object downloaded via s3:GetObject still requires the caller to be authorized in both the KMS key policy and their IAM policy to decrypt the data. Without an explicit kms:Decrypt Allow, any decryption attempt returns an AccessDenied error even though the S3 GET itself may be permitted.
- ✓
s3:GetObject
Why this is correct
s3:GetObject is explicitly allowed by a statement granting read access to the object ARN, typically expressed as arn:aws:s3:::bucket/*, so downloading an object is authorized. This data-plane permission is the counterpart to s3:ListBucket: the list action lets the caller discover what objects exist, while GetObject restricts the request to retrieving a specific object's contents. As long as no explicit Deny overrides this Allow, the action succeeds under this policy.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.