Courseiva
Infrastructure Security →hardMultiple Choice

SCS-C02 Infrastructure Security Practice Question

Exhibit

Refer to the exhibit.

Exhibit: (IAM policy JSON)
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ec2:DescribeInstances",
        "ec2:StartInstances",
        "ec2:StopInstances"
      ],
      "Resource": "arn:aws:ec2:us-east-1:123456789012:instance/*"
    },
    {
      "Effect": "Allow",
      "Action": [
        "ec2:DescribeInstances",
        "ec2:DescribeInstanceStatus"
      ],
      "Resource": "*"
    }
  ]
}

Refer to the exhibit. A security engineer is reviewing this IAM policy attached to a user. The user reports that they are able to stop and start instances, but they cannot terminate instances. However, the engineer notices that there is no explicit deny for termination. Why is the user unable to terminate instances?

⚠ Common exam trap

Candidates often assume the absence of an explicit deny means the action is allowed, but AWS IAM defaults to implicit deny for any action not explicitly allowed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy does not include an explicit Allow for ec2:TerminateInstances.

IAM policies operate on an explicit allow model. Even though there is no explicit deny for ec2:TerminateInstances, the user is unable to terminate instances because the policy does not include an explicit Allow action for ec2:TerminateInstances. Without an explicit Allow, the default behavior is to deny the action, regardless of whether a deny statement is present.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The policy does not include an explicit Allow for ec2:TerminateInstances.

    Why this is correct

    The policy contains separate Action and Resource elements, and IAM permits an action only when an explicit Allow statement matches that action. Because ec2:TerminateInstances appears nowhere in the first statement's Action list (which grants Start and Stop) or in the second statement's Describe-only list, the action is implicitly denied by IAM's default-deny evaluation. Without an explicit Allow, no other statement or wildcard can rescue it; the request fails with an UnauthorizedOperation error.

  • ✗

    The second statement's Resource is set to '*' but the Action list does not include termination.

    Why it's wrong here

    The second statement uses Resource: '*' and lists only ec2:Describe* actions, such as DescribeInstances and DescribeTags. A Resource wildcard does grant those specific actions across all resources, but it grants only the actions named in the statement; ec2:TerminateInstances is not among them. Therefore, this option misidentifies the cause: the statement's Resource is not too narrow, but its Action list simply does not include the termination API call, so this statement is not the source of an Allow for it.

  • ✗

    The first statement's Resource element is too restrictive and does not include the termination API call.

    Why it's wrong here

    The first statement's Resource element specifies an instance ARN (arn:aws:ec2:region:account:instance/*), which is exactly the resource type that ec2:TerminateInstances operates on under AWS's resource-level authorization model. The Resource element only identifies the target of the actions, not which API calls are allowed; that is the role of the Action element. Because the omission is in the Action list, the Resource is not 'too restrictive' nor does it need to include the API call—this explanation confuses two distinct parts of the policy.

  • ✗

    The policy has a syntax error that prevents termination from being evaluated.

    Why it's wrong here

    An IAM policy is a JSON document, and this policy uses the required structure: Version, Statement, Effect, Action, and Resource, with correct syntax, comma placement, and braces. If the policy had a syntax error, IAM would reject it during validation or the entire policy would be non-functional, not just block one action. Termination is unevaluated because the action is missing from the allowed list, not because the policy fails to parse or fails schema validation.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.