Courseiva

SCS-C02 Identity and Access Management Practice Question

Network Topology
$ aws iam simulate-custom-policypolicy-input-list '{"Version":"2012-10-17"action-names ec2:DescribeInstances ec2:RunInstancesresource-arns 'arn:aws:ec2:us-east-1:123456789012:instance/*'Refer to the exhibit.```"EvaluationResults": ["EvalActionName": "ec2:DescribeInstances","EvalResourceName": "arn:aws:ec2:us-east-1:123456789012:instance/*","EvalDecision": "allowed"},"EvalActionName": "ec2:RunInstances","EvalDecision": "explicitDeny"

Refer to the exhibit. A security engineer runs the IAM Policy Simulator with the provided policy input. The result shows 'explicitDeny' for ec2:RunInstances even though the policy only contains an Allow. What is the most likely reason?

⚠ Common exam trap

SCS-C02 often tests the misconception that the simulator only evaluates the policy you paste in — candidates forget that explicit Deny from SCPs, permissions boundaries, or other attached policies takes precedence and produces the explicitDeny result.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user has an attached policy or SCP that explicitly denies ec2:RunInstances.

The IAM Policy Simulator evaluates the effective permissions by combining all applicable policies — identity-based policies, resource-based policies, permissions boundaries, SCPs, and session policies. An 'explicitDeny' result means some policy in the evaluation chain contains an explicit Deny statement for ec2:RunInstances, which always overrides any Allow. Since the input policy only has an Allow, the deny must originate from an attached policy or an SCP in the account hierarchy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The user has an attached policy or SCP that explicitly denies ec2:RunInstances.

    Why this is correct

    An explicit Deny in any attached identity policy, permissions boundary or AWS Organizations SCP always overrides Allow, producing explicitDeny in the simulator. The Allow in the supplied policy cannot take effect while that deny remains in force.

  • ✗

    The policy input has a syntax error.

    Why it's wrong here

    A syntax error causes the Simulator to reject the policy or return an error, not to evaluate it and report explicitDeny. ExplicitDeny requires a matching Deny statement. Syntax validation matters when authoring policies before simulation, but malformed JSON never yields a simulated deny result.

  • ✗

    The simulate-custom-policy command does not support ec2:RunInstances.

    Why it's wrong here

    The IAM Policy Simulator supports all EC2 actions including ec2:RunInstances, so an unsupported-action error cannot produce explicitDeny. It is tempting because unsupported actions do exist in some AWS tooling, and checking action support would be correct when the simulator returns an error rather than a deny decision.

  • ✗

    The resource ARN is incorrect for ec2:RunInstances.

    Why it's wrong here

    An incorrect resource ARN produces an implicit deny (no matching Allow), not explicitDeny. The Simulator reports explicitDeny only when a Deny statement matches, so the ARN cannot be the cause. Correct ARNs matter when scoping resource-level permissions, but a mismatch here would simply leave the action unmatched.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.