An IAM policy includes the following condition: "StringNotEquals": {"aws:SourceArn": "arn:aws:ec2:us-east-1:123456789012:instance/*"}. What is the effect of this condition when attached to an IAM role?
Trap 1: Denies all requests from EC2 instances
The StringNotEquals operator tests whether the condition key's value does not match the specified string. When the source ARN matches the exact pattern in the policy, the condition evaluates to false, so the Deny effect does not apply and the request is not denied. Therefore, requests from EC2 instances that match the specified account and region ARN are unaffected; only non-matching sources — including EC2 instances outside the specified scope — would be denied.
Trap 2: Allows the role to be assumed only by EC2 instances in the…
This option misreads a Deny statement as an Allow effect. StringNotEquals in a Deny statement means that requests are blocked when the source ARN differs from the specified value; it does not create a positive permission that allows role assumption. To restrict assumption to a specific account and region, you would need an explicit Allow statement on sts:AssumeRole with a StringEquals condition, not a Deny statement with StringNotEquals. A standalone Deny cannot grant access, so this explanation is incorrect.
Trap 3: Allows any request that comes from an EC2 instance regardless of…
This option incorrectly assumes the policy allows all EC2 instances from any account. The condition is not a broad EC2-based allow; it is a Deny with a StringNotEquals condition on an ARN that is scoped to a specific account and region. An EC2 instance from a different account or region will have an ARN that does not match the pattern, making the condition true and triggering the Deny. Furthermore, a Deny statement never grants permissions — if there is no explicit allow in the same policy, the request would be implicitly denied by default, so the statement cannot be interpreted as an allow.
- A
Denies all requests from EC2 instances
Why it fails: The StringNotEquals operator tests whether the condition key's value does not match the specified string. When the source ARN matches the exact pattern in the policy, the condition evaluates to false, so the Deny effect does not apply and the request is not denied. Therefore, requests from EC2 instances that match the specified account and region ARN are unaffected; only non-matching sources — including EC2 instances outside the specified scope — would be denied.
- B
Allows the role to be assumed only by EC2 instances in the specified account and region
Why it fails: This option misreads a Deny statement as an Allow effect. StringNotEquals in a Deny statement means that requests are blocked when the source ARN differs from the specified value; it does not create a positive permission that allows role assumption. To restrict assumption to a specific account and region, you would need an explicit Allow statement on sts:AssumeRole with a StringEquals condition, not a Deny statement with StringNotEquals. A standalone Deny cannot grant access, so this explanation is incorrect.
- C
Denies requests that do not originate from an EC2 instance in the specified account and region
This option correctly recognizes how StringNotEquals works in a Deny statement. The policy sets a condition key (such as ec2:SourceInstanceARN or aws:SourceArn) to a specific ARN pattern that includes a particular account and region. When a request originates from a source whose ARN does not match that pattern — for example, an instance in another account, another region, or a non-EC2 principal — the StringNotEquals condition is true and the Deny effect blocks the request. Conversely, if the source ARN matches the specified pattern, the condition is false and the Deny does not fire, so the request is allowed. This matches the given answer.
- D
Allows any request that comes from an EC2 instance regardless of account
Why it fails: This option incorrectly assumes the policy allows all EC2 instances from any account. The condition is not a broad EC2-based allow; it is a Deny with a StringNotEquals condition on an ARN that is scoped to a specific account and region. An EC2 instance from a different account or region will have an ARN that does not match the pattern, making the condition true and triggering the Deny. Furthermore, a Deny statement never grants permissions — if there is no explicit allow in the same policy, the request would be implicitly denied by default, so the statement cannot be interpreted as an allow.