A security engineer is reviewing the following IAM policy attached to a role. Which TWO actions are allowed by this policy? (Choose two.) ```json { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:ListBucket", "s3:GetObject" ], "Resource": "*" } ] } ```
The policy includes an explicit Allow statement for s3:ListBucket on the bucket resource, so this action is permitted. IAM defaults to deny only for actions not covered by any applicable Allow, and because no explicit or resource-based Deny applies to this principal for that bucket, the ListBucket call is authorized. The permission is scoped to the bucket ARN, not individual objects, which matches the resource type required by the ListBucket API.
Why this answer
Option A (s3:ListBucket) is correct because the policy's Action list explicitly includes "s3:ListBucket" with Effect Allow and Resource "*", so listing any S3 bucket is permitted. Option E (s3:GetObject) is correct because "s3:GetObject" is also explicitly listed in the same Allow statement, granting read access to objects across all resources. The unmarked options do not belong because the policy only allows the two S3 actions named; ec2:TerminateInstances, iam:CreateUser, and kms:Decrypt are not present in the Action list, and IAM policies are deny-by-default for any action not explicitly allowed.
Exam trap
SCS-C02 often tests the principle of least privilege and implicit deny — candidates may incorrectly assume that unrelated actions like ec2:TerminateInstances are allowed because the policy uses Resource: "*", confusing resource scope with action scope.