Courseiva
Security and Compliance →mediumMultiple Choice

IAM Policy Evaluation with IP Condition and Deny

Exhibit

Refer to the exhibit.

IAM Policy JSON:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ec2:RunInstances",
        "ec2:TerminateInstances",
        "ec2:StartInstances",
        "ec2:StopInstances"
      ],
      "Resource": "arn:aws:ec2:us-east-1:123456789012:instance/*",
      "Condition": {
        "StringEquals": {
          "ec2:ResourceTag/Environment": "Production"
        }
      }
    }
  ]
}

Refer to the exhibit. An IAM user has this policy attached. The user tries to start an EC2 instance that has no tags. What will happen?

⚠ Common exam trap

Watch out — candidates often assume a missing tag causes the condition to be ignored or treated as 'not applicable', but in IAM, a missing tag causes the condition to evaluate to false, leading to an implicit deny.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user will be denied because the instance does not have the required tag

The IAM policy includes a condition that requires the EC2 instance to have a tag with key 'Environment' and value 'Production'. When the instance has no tags, the condition evaluates to false, and the default behavior for IAM policies is to deny access when a condition is not met. Since the policy does not explicitly allow the action without the tag, the request is implicitly denied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user will be allowed because the condition only applies if the tag exists

    Why it's wrong here

    This statement is incorrect because the condition is not optional. In IAM policy evaluation, a condition key must be satisfied for the allow to apply; if the resource lacks the aws:ResourceTag/Environment tag, the condition evaluates to false rather than being skipped. Since the condition is part of the allow statement, a false condition makes the allow inapplicable, so the request is implicitly denied.

  • ✗

    The user will be allowed because the resource ARN includes a wildcard

    Why it's wrong here

    The wildcard in the Resource ARN only determines which resources the statement can apply to; it does not relax any condition requirements. Even if the ARN pattern matches the instance, the statement still requires the condition aws:ResourceTag/Environment = 'Production' to evaluate true. Because the instance lacks that tag, the allow statement does not grant the action. Thus a resource ARN wildcard does not change the outcome.

  • ✗

    The user will be allowed because the policy does not explicitly deny the action

    Why it's wrong here

    IAM uses an explicit default-deny model, so an action is permitted only when an applicable allow statement matches the request. The absence of an explicit deny does not create permission; the allow statement in the policy must fully match, including satisfying all conditions. Here the condition fails, so no allow applies and the action is denied implicitly. Therefore the statement is wrong.

  • ✓

    The user will be denied because the instance does not have the required tag

    Why this is correct

    The policy includes a condition that requires the instance to have a tag key Environment with value 'Production'. Since the instance in question does not have that tag, the condition is not met, so the allow statement cannot be applied. IAM's default is to deny any request not explicitly allowed, so the user is denied permission to start the instance. The condition must be satisfied even if the resource ARN matches.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Refer to the exhibit. An IAM policy is attached to a user. What is the effective permission regarding the s3:DeleteObject action on the example-bucket?

easy
  • ✓ A.Denied because of the explicit Deny statement
  • B.Denied because the action is not allowed explicitly
  • C.Allowed because the Allow statement is listed first
  • D.Allowed because the Deny statement has a typo

Why A: The effective permission is Denied because of the explicit Deny statement. In AWS IAM policy evaluation, an explicit Deny always overrides any Allow, regardless of the order in which statements appear or whether the action is otherwise permitted. Since the policy contains an explicit Deny for s3:DeleteObject on example-bucket, the request is denied.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.