hardMultiple Choice
SSCP Explicit Deny Practice Question
Exhibit
Refer to the exhibit. The following IAM policy is attached to a user:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::corporate-data/*"
},
{
"Effect": "Deny",
"Action": "s3:PutObject",
"Resource": "arn:aws:s3:::corporate-data/*"
}
]
}Based on the exhibit, if the user attempts to upload (write) a file to the shared data repository corporate-data, what is the result?
⚠ Common exam trap
It's easy for candidates to assume an explicit allow for write would override a deny, but in access control policies, an explicit deny always wins, making the presence of any deny statement the decisive factor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Denied because the explicit deny overrides any allow
The resource's access control policy includes an explicit deny statement that denies write permission for the user's principal. In standard access control policy evaluation, an explicit deny always overrides any allow, regardless of other permissions. Therefore, even if other statements allow write access, the explicit deny blocks the upload.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allowed because the access policy likely allows public writes
Why it's wrong here
The exhibit's policy grants read access only, so a public-write allowance is not shown; uploads would be denied. Public write policies suit anonymous drop-box repositories where untrusted users submit files, not a controlled corporate-data share with defined permissions.
- ✓
Denied because the explicit deny overrides any allow
Why this is correct
In NTFS, an explicit deny entry takes precedence over any inherited or explicit allow, so the write attempt fails regardless of granted permissions. The deny ACE on the corporate-data repository therefore blocks the upload outright, satisfying the exhibit's constraint that write access is refused.
- ✗
Denied because write permission is not explicitly allowed
Why it's wrong here
The exhibit shows the policy grants read access, so write is denied by omission, not because permissions must be explicit. This option would be correct if the platform defaulted to deny-all and the policy listed only read.
- ✗
Allowed because the policy also allows read access
Why it's wrong here
Read access and write access are separate permissions; granting read does not imply write, so the upload is denied. This option would be right only if the policy explicitly listed write alongside read for that repository.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.