Courseiva

SCS-C02 Identity and Access Management Practice Question

An IAM user reports that they are unable to launch an EC2 instance in a specific VPC. The user has an IAM policy that allows ec2:RunInstances but does not grant permission for the subnet resource. The VPC has a network ACL that allows all inbound and outbound traffic. What is the most likely cause of the failure?

⚠ Common exam trap

SCS-C02 often tests the misconception that RunInstances only needs permission on the instance resource — candidates forget that the subnet, AMI, security group, and volume are also required resources in the IAM evaluation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IAM policy does not grant permission to use the subnet.

ec2:RunInstances requires permissions on multiple resource types — the instance, the AMI, the subnet, the security group, the key pair, and the volume. If the IAM policy grants ec2:RunInstances on * for the instance resource but omits the subnet ARN (or uses a Resource that does not include the subnet), the request fails with an unauthorized error even though the VPC and NACL are permissive. The fix is to include the subnet ARN in the Resource element or use a wildcard that covers it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IAM policy does not grant permission to use the VPC.

    Why it's wrong here

    The VPC is a regional container that holds subnets and other resources, and it does not appear as a resource type in ec2:RunInstances authorization. IAM permission checks for a launch action evaluate resources like the subnet, network interface, and security group, not the VPC itself. Therefore, a missing VPC-level grant would never produce a launch failure.

  • ✗

    The security group associated with the instance is blocking the launch.

    Why it's wrong here

    Security groups are stateful firewalls attached to network interfaces, and they only evaluate traffic after the instance has successfully launched. The RunInstances API call is an IAM-authorized control-plane operation that creates the instance and ENI, and a security group's deny rules cannot reject that API call. If the security group were misconfigured, you might fail to SSH or ping, but the instance would still appear in the console as running.

  • ✓

    The IAM policy does not grant permission to use the subnet.

    Why this is correct

    Launching an instance with a resource-scoped IAM policy requires the ec2:RunInstances action to be granted on each dependent resource, including the subnet ARN (e.g., arn:aws:ec2:region:account-id:subnet/subnet-...). If the policy's Resource element omits the subnet but references the instance or AMI, the request fails with an explicit access denied because RunInstances is a 'create' action that conditionally requires subnet permission. This is the exact reason a user can have broad EC2 permissions yet still be blocked for a specific subnet.

  • ✗

    The network ACL is blocking the launch request.

    Why it's wrong here

    Network ACLs operate at the subnet boundary as stateless packet filters for data-plane traffic, not for control-plane API calls. The RunInstances request is an HTTPS API call to the EC2 service, and it is authorized by IAM, never inspected by a network ACL. Even if a NACL rule denies all inbound traffic on the subnet, the instance launch and its underlying network interface creation will proceed successfully.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.