Understanding Explicit Deny in IAM Policy Simulator Output
Network Topology
Refer to the exhibit. A security engineer runs the 'simulate-custom-policy' command to test a policy. The output shows 'explicitDeny' for ec2:RunInstances. What is the most likely reason?
Quick Answer
The answer is that the policy does not include ec2:RunInstances in the Action list. This is the most likely reason for an explicitDeny in the IAM policy simulator output because the simulator evaluates the effective permissions of a policy; when an action like ec2:RunInstances is not explicitly allowed, and no other policy grants it, the simulator marks it as an explicit deny rather than an implicit deny. On the AWS Certified Security Specialty SCS-C02 exam, this concept tests your understanding of how the simulator distinguishes between actions that are forbidden by a Deny statement and those simply not listed in an Allow statement—a common trap is confusing an explicit deny from the simulator with a Deny effect in the policy. Remember, the simulator’s explicitDeny flag means the action is not allowed by the policy being tested, not that a Deny statement exists. A helpful memory tip: if it’s not in the Allow list, the simulator calls it explicitDeny.
⚠ Common exam trap
SCS-C02 often tests the difference between implicit and explicit deny, and candidates may incorrectly attribute an explicit deny to a missing Allow statement rather than an actual Deny statement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy includes an explicit Deny statement for ec2:RunInstances
In AWS IAM policy evaluation, an explicit Deny statement always overrides any Allow. The simulate-custom-policy command returns 'explicitDeny' when the action is explicitly denied by a Deny statement in the policy. Therefore, the most likely reason is that the policy includes an explicit Deny for ec2:RunInstances.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy does not include ec2:RunInstances in the Action list
Why it's wrong here
Omitting ec2:RunInstances from the Action list produces an implicit deny, whereas the simulation reports explicitDeny, meaning a Deny statement matched. It is tempting because missing actions are the usual cause of access failures, and would be correct if the result had shown implicitDeny.
- ✓
The policy includes an explicit Deny statement for ec2:RunInstances
Why this is correct
An explicit Deny statement always overrides any Allow in IAM policy evaluation. The simulate-custom-policy output returning explicitDeny confirms a matching Deny statement exists for ec2:RunInstances, so the request is blocked regardless of any Allow statements present.
- ✗
The policy allows ec2:Describe* but the action ec2:RunInstances is not a Describe action
Why it's wrong here
A missing ec2:RunInstances allow yields an implicit deny, not the explicitDeny shown, so the Describe wildcard is irrelevant to the result. It is tempting because action-name mismatches are a common cause of failed calls, and would be correct if the output had reported implicitDeny instead.
- ✗
The policy uses a Resource of '*' which does not include the required resources
Why it's wrong here
A Resource of '*' matches every resource, so it cannot produce an explicitDeny; explicit denies come from a Deny statement matching the action. It is tempting because wildcards often cause unintended matches, and would be correct if the policy used a narrower ARN that excluded the target instance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security engineer runs the IAM policy simulator with a custom policy. The output shows the above. Which statement is true about the policy?
medium- A.The policy allows iam:DeleteUser but denies iam:CreateUser.
- B.The policy allows all actions by default.
- ✓ C.The policy contains a statement that explicitly denies iam:DeleteUser.
- D.The policy has no effect because the simulator returned errors.
Why C: The policy simulator shows an explicit deny for iam:DeleteUser, confirming that a deny statement exists in the policy. Option C is correct because the explicit deny means the policy explicitly denies iam:DeleteUser. Option A is incorrect because the simulator does not indicate that iam:CreateUser is denied. Option B is incorrect because the explicit deny overrides any default allow. Option D is incorrect because the simulator returned an explicit deny, not errors.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.