SCS-C02 Management and Security Governance Practice Question
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": "ec2:RunInstances",
"Resource": "arn:aws:ec2:*:*:instance/*",
"Condition": {
"StringNotEquals": {
"ec2:InstanceType": "t2.micro"
}
}
}
]
}This SCP is attached to an organizational unit (OU). A developer in an account within the OU tries to launch a t2.small instance. What is the outcome?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The launch fails because the SCP denies non-t2.micro instances.
The SCP denies ec2:RunInstances if the instance type is not t2.micro. Since t2.small is not t2.micro, the condition matches, and the action is denied. Option A is wrong because the SCP does not deny all RunInstances actions; it only denies those that do not match the condition. Option B is wrong because the launch fails, not succeeds. Option D is wrong because SCPs apply to all principals in the account, including developers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The launch fails because the SCP denies all RunInstances actions.
Why it's wrong here
The SCP does not deny all RunInstances actions; its Deny statement is scoped with a condition key such as ec2:InstanceType, so the denial only applies when the instance type is not t2.micro. A blanket deny of RunInstances would block every launch, including t2.micro, which contradicts the conditional structure described in the scenario. Therefore, the failure of the t2.small launch is not caused by a wholesale denial of the RunInstances action.
- ✗
The launch succeeds because the SCP allows t2.micro only.
Why it's wrong here
This option contains a fatal contradiction: saying the SCP 'allows t2.micro only' actually means it denies every other instance type, including t2.small, so the launch should not succeed. SCPs do not confer a positive allow for a specific resource; they act as a guardrail that either permits or blocks actions based on their statements. Since the developer launched t2.small, the accurate outcome is a denial, not a success, making this option incorrect.
- ✓
The launch fails because the SCP denies non-t2.micro instances.
Why this is correct
The SCP's Deny effect triggers when the ec2:InstanceType condition does not equal t2.micro, typically using StringNotEquals. A t2.small instance does not match t2.micro, so the condition evaluates to true and the Deny takes effect, blocking the RunInstances call. Since SCPs are implicit deny guardrails applied at the OU level, not even the developer's IAM permissions can override this denial, so the launch fails with an unauthorized operation error.
- ✗
The launch succeeds because SCPs do not apply to developers.
Why it's wrong here
SCPs apply to all principals in an account, including developers, so the deny on non-compliant instance types blocks the t2.small launch regardless of the user's role. This option is tempting because IAM permission boundaries or resource-based policies can exempt developers from certain restrictions, but SCPs operate at the account level as a guardrail that cannot be overridden by any IAM entity.
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.