SOA-C02 IAM Policy Evaluation Practice Question
A SysOps administrator is troubleshooting an IAM policy that is not granting the expected permissions. The policy has a Deny effect on a specific action, but the user is still able to perform that action. What is the most likely reason?
⚠ Common exam trap
SOA-C02 often tests the misconception that any Deny statement automatically blocks access — candidates forget that a Deny with an unmet condition is effectively inert, and they overlook the condition evaluation step in the IAM policy evaluation flow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Deny statement includes a condition that is not met by the request
An explicit Deny in IAM only takes effect when the condition attached to that Deny statement evaluates to true for the request. If the Deny statement includes a condition (such as a specific IP range, MFA requirement, or time window) that the current request does not satisfy, the Deny does not apply, and an Allow from another policy can grant access. This is the most likely reason a user can still perform the action despite a Deny statement existing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Deny statement is listed after an Allow statement in the policy
Why it's wrong here
The order of statements within an IAM policy has no bearing on the outcome. IAM aggregates and evaluates all statements from all relevant policies, and an explicit Deny is always enforced regardless of whether it appears before or after an Allow statement in the document.
- ✗
IAM policies do not support deny statements with conditions
Why it's wrong here
IAM policies fully support Deny statements with condition blocks; the Condition element can be attached to statements with Effect: Deny just as easily as to Allow statements. For example, you can write a Deny that only applies when aws:RequestedRegion equals a specific value, so denying that conditions are unsupported is factually wrong.
- ✓
The Deny statement includes a condition that is not met by the request
Why this is correct
This is the correct option. IAM evaluates the Condition element of a Deny statement before treating that statement as an effective deny; if the request's context does not satisfy the condition, the Deny statement is skipped entirely. Once that Deny is out of the way, the default-implicit-deny behavior is replaced by any applicable Allow policies, which then permit the action.
- ✗
The user has an attached AWS managed policy that allows the action
Why it's wrong here
An explicit Deny always overrides any Allow, including allowances granted by AWS managed policies, when the Deny actually applies to the request. In IAM's evaluation logic, explicit deny takes precedence over every allow, so the presence of an attached AWS managed policy that allows the action would not defeat a matching explicit Deny.
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SOA-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A SysOps administrator is troubleshooting an issue where an IAM user is unable to launch an EC2 instance in a specific subnet. The user has the following IAM policy: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "ec2:RunInstances", "Resource": "*", "Condition": { "StringEquals": { "ec2:Subnet": "subnet-12345" } } } ] } What is the likely cause of the failure?
hard- A.The policy does not allow the 'ec2:DescribeSubnets' action, so the user cannot list subnets.
- ✓ B.The user is not specifying the subnet ID when launching the instance.
- C.The policy denies all subnets except subnet-12345.
- D.The condition key 'ec2:Subnet' is not supported for RunInstances.
Why B: The IAM policy uses the condition key 'ec2:Subnet' with StringEquals, which means the RunInstances call is only allowed when the request includes a subnet ID matching subnet-12345. If the user launches an instance without specifying a subnet (for example, relying on the default VPC subnet or omitting the subnet parameter), the condition key is absent from the request context and the condition evaluates to false, so the call is denied. The likely cause is therefore that the user is not specifying the required subnet ID.
Variation 2. An S3 bucket policy is shown in the exhibit. The AdminRole attempts to upload an object to my-bucket without specifying any server-side encryption header. What will happen?
hard- A.The upload fails because the Allow statement requires encryption, but the Deny statement is evaluated first.
- B.The upload succeeds because the Allow statement grants permission to the AdminRole.
- C.The upload succeeds because the Deny statement does not apply to the AdminRole.
- ✓ D.The upload fails because the Deny statement denies PutObject without encryption.
Why D: The Deny statement denies PutObject when encryption is not aws:kms. Since the request has no encryption header, it does not equal aws:kms, so the Deny applies and the upload fails. The Allow statement allows the action only when encryption is aws:kms, so without encryption, it does not apply. Because the Deny overrides Allow, the upload is denied. Option A is wrong because the Allow does not apply. Option B is wrong because the Deny applies. Option C is wrong because the Deny does apply to the AdminRole.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.