Courseiva
Security and Compliance →easyMultiple Choice

SOA-C02 Security and Compliance Practice Question

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "ec2:DescribeInstances",
      "Resource": "*"
    },
    {
      "Effect": "Allow",
      "Action": "ec2:RunInstances",
      "Resource": "arn:aws:ec2:us-east-1:123456789012:instance/*",
      "Condition": {
        "StringEquals": {
          "ec2:InstanceType": "t2.micro"
        }
      }
    }
  ]
}

Refer to the exhibit. An IAM policy allows a user to run instances only of type t2.micro. What happens when the user tries to run a t2.small instance?

⚠ Common exam trap

SOA-C02 often tests the misconception that a policy allowing an action (ec2:RunInstances) automatically permits all variations of that action, ignoring the effect of condition keys that narrow the scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The request is denied because t2.small does not match the condition.

The IAM policy includes a condition that restricts ec2:RunInstances to the t2.micro instance type. When the user attempts to launch a t2.small instance, the condition evaluates to false, so the statement does not apply and the request is implicitly denied. IAM policies are deny-by-default, so the absence of an allow results in denial.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The request is allowed because the policy allows ec2:RunInstances.

    Why it's wrong here

    The IAM policy does include ec2:RunInstances as an action, but the statement is qualified by a condition that requires the instance type to be exactly t2.micro. When a condition is present, the entire allow statement is only effective if all conditions are true. Since the requested instance type is t2.small, the condition evaluates false, so this allow statement does not apply, resulting in an implicit deny.

  • ✗

    The request is denied because there is an explicit deny on ec2:RunInstances.

    Why it's wrong here

    This statement misidentifies the reason for the denial. IAM evaluation logic defaults to deny, and an explicit deny statement would override any allows; however, nothing in this policy contains an explicit deny for ec2:RunInstances. The request fails because the sole allow statement's condition on ec2:InstanceType is not satisfied, making the lack of a matching allow the cause, not a deny action.

  • ✗

    The request is allowed because the condition only applies to the resource ARN, not the instance type.

    Why it's wrong here

    While condition keys often use resource ARNs, this policy uses the condition key ec2:InstanceType, which is evaluated against the request's instance type parameter during RunInstances. The condition is not applied solely to the ARN; it directly constrains the created resource's type. Because the condition explicitly requires t2.micro, launching t2.small violates that condition, so the allow does not grant permission.

  • ✓

    The request is denied because t2.small does not match the condition.

    Why this is correct

    The correct outcome is an implicit deny: the request for a t2.small instance fails the policy statement's condition that instanceType equals t2.micro. In IAM, for a request to be allowed, an allow statement must match the action, resource, and any specified conditions; here the action matches, but the condition does not. Since no other statement provides a different allow, the default deny takes effect.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.