Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company has a single AWS account with multiple IAM users. The security team wants to ensure that no IAM user can create or modify VPC resources. The SysOps administrator creates a managed policy that denies ec2:CreateVpc, ec2:DeleteVpc, ec2:ModifyVpcAttribute, and similar actions. The policy is attached to all IAM users via a group. However, after a week, a user reports that they were able to create a VPC. The administrator checks CloudTrail and confirms that the user created the VPC. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user created the VPC using AWS CloudFormation with a service role that had full EC2 access.

The most likely cause is that the user created the VPC using AWS CloudFormation with a service role that had full EC2 access (including ec2:CreateVpc). IAM policies applied to a user do not affect actions taken by AWS services like CloudFormation when a service role is used, because the service role itself grants permissions. Even though the user's group policy denies VPC creation, the CloudFormation service role bypasses the user's IAM policies. This is a known pitfall: service roles can allow users to perform actions that their own IAM policies deny, if they have permission to pass the role.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user used the AWS Management Console, which does not enforce IAM policies.

    Why it's wrong here

    The AWS Management Console is not exempt from IAM; it invokes the same public APIs on behalf of the signed-in user, and every request is evaluated against the user's effective permissions. If the user lacked ec2:CreateVpc, the console would return an authorization error rather than silently allow the action. Therefore, this is incorrect.

  • ✗

    The user had an inline policy that allowed ec2:CreateVpc, overriding the group policy.

    Why it's wrong here

    IAM policy evaluation uses a default-deny model, and an explicit deny in any policy always overrides every allow, regardless of whether the allow is in an inline policy or a group policy. An inline policy that allows ec2:CreateVpc cannot override a group policy that denies it, so the user would still be blocked. Hence, this cannot explain the successful VPC creation.

  • ✗

    The policy was attached to the user's group, but the user was not a member of that group.

    Why it's wrong here

    The scenario states that the policy was attached to all users through the group, which implies every user, including this one, was a member of that group. If the user were not a member, the group policy wouldn't apply, but that would not grant new permissions; they would simply not inherit the deny. Since the premise contradicts membership, this option is not a valid explanation.

  • ✓

    The user created the VPC using AWS CloudFormation with a service role that had full EC2 access.

    Why this is correct

    With AWS CloudFormation, you can specify an IAM service role (or just a role) that CloudFormation assumes to create stack resources. If the user launched the stack with a role that includes ec2:CreateVpc, the role's permissions authorize the VPC creation, not the user's own policies, provided the user had iam:PassRole for that role. This is a legitimate way for a user without direct EC2 create permission to create a VPC.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.