Courseiva
hardMultiple Choice

SSCP Explicit Deny Practice Question

Exhibit

Refer to the exhibit. The following IAM policy is attached to a user:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::corporate-data/*"
    },
    {
      "Effect": "Deny",
      "Action": "s3:PutObject",
      "Resource": "arn:aws:s3:::corporate-data/*"
    }
  ]
}

Based on the exhibit, if the user attempts to upload (write) a file to the shared data repository corporate-data, what is the result?

⚠ Common exam trap

It's easy for candidates to assume an explicit allow for write would override a deny, but in access control policies, an explicit deny always wins, making the presence of any deny statement the decisive factor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Denied because the explicit deny overrides any allow

The resource's access control policy includes an explicit deny statement that denies write permission for the user's principal. In standard access control policy evaluation, an explicit deny always overrides any allow, regardless of other permissions. Therefore, even if other statements allow write access, the explicit deny blocks the upload.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Allowed because the access policy likely allows public writes

    Why it's wrong here

    The exhibit's policy grants read access only, so a public-write allowance is not shown; uploads would be denied. Public write policies suit anonymous drop-box repositories where untrusted users submit files, not a controlled corporate-data share with defined permissions.

  • ✓

    Denied because the explicit deny overrides any allow

    Why this is correct

    In NTFS, an explicit deny entry takes precedence over any inherited or explicit allow, so the write attempt fails regardless of granted permissions. The deny ACE on the corporate-data repository therefore blocks the upload outright, satisfying the exhibit's constraint that write access is refused.

  • ✗

    Denied because write permission is not explicitly allowed

    Why it's wrong here

    The exhibit shows the policy grants read access, so write is denied by omission, not because permissions must be explicit. This option would be correct if the platform defaulted to deny-all and the policy listed only read.

  • ✗

    Allowed because the policy also allows read access

    Why it's wrong here

    Read access and write access are separate permissions; granting read does not imply write, so the upload is denied. This option would be right only if the policy explicitly listed write alongside read for that repository.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.