SOA-C02 Deployment, Provisioning, and Automation Practice Question
Exhibit
Refer to the exhibit.
```
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "cloudformation:*",
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"ec2:Describe*",
"ec2:Create*",
"ec2:RunInstances",
"ec2:TerminateInstances"
],
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"iam:PassRole"
],
"Resource": "arn:aws:iam::123456789012:role/Admin"
}
]
}
```A SysOps administrator is creating a CloudFormation stack that requires an IAM role to be passed to EC2 instances. The administrator is using the IAM policy shown in the exhibit. The stack creation fails with an error indicating insufficient permissions to pass the role. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The iam:PassRole permission is restricted to a specific role ARN that does not match the role the administrator is trying to pass.
The IAM policy likely includes an iam:PassRole action restricted to a specific role ARN (e.g., 'arn:aws:iam::account:role/Admin'), but the CloudFormation stack is attempting to pass a different role. This causes an insufficient permissions error because the PassRole permission is scoped to that specific role. Option A is incorrect because cloudformation:* includes all CloudFormation actions, including creating stacks. Option B is incorrect because the policy uses cloudformation:*, which implicitly includes CreateStack. Option C is incorrect because ec2:RunInstances is not required for passing an IAM role; the necessary permission is iam:PassRole.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The cloudformation:* action does not include permission to create stacks.
Why it's wrong here
The statement that cloudformation:* does not include permission to create stacks is incorrect because the wildcard (*) is an IAM action wildcard that matches every CloudFormation action, including CreateStack, UpdateStack, DeleteStack, and all other API calls. In IAM policy evaluation, a wildcard in the Action element grants all actions for that service, and CloudFormation-specific permissions like cloudformation:CreateStack are implicitly included. Therefore, this is not the cause of the stack creation failure.
- ✗
The policy does not include the cloudformation:CreateStack action.
Why it's wrong here
The claim that the policy lacks cloudformation:CreateStack is false because the policy explicitly grants cloudformation:* (or equivalent wildcard) which encompasses all CloudFormation actions, including CreateStack. IAM policy evaluation uses the most specific matching statement, but a wildcard grant for the entire service covers every action in that service, so there is no missing permission for CreateStack. The failure must be caused by a different permission, not the absence of CreateStack.
- ✗
The ec2:RunInstances permission is missing from the policy.
Why it's wrong here
The assertion that ec2:RunInstances is missing is incorrect because the policy grants ec2:RunInstances, and even if it were missing, the stack creation failure is occurring before any EC2 instance launch. CloudFormation first performs IAM permission validation, including checking the iam:PassRole permission, before provisioning resources. Missing RunInstances would produce a different error (EC2 unauthorized), not a PassRole failure.
- ✓
The iam:PassRole permission is restricted to a specific role ARN that does not match the role the administrator is trying to pass.
Why this is correct
The correct explanation is that the iam:PassRole permission in the policy is scoped to a specific role ARN (e.g., arn:aws:iam::123456789012:role/Admin), but the CloudFormation stack is configured to use a different IAM role, such as a dedicated stack role or a role named 'StackRole'. When CloudFormation attempts to pass that role to the EC2 instances or other resources, IAM evaluates the PassRole action and denies it because the ARN does not match the one allowed. This is a classic IAM PassRole mismatch error and is precisely why the stack creation fails.
Go deeper
Related to this question
About these practice questions
One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.