exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C02 exam

Exam AWS Certified Solutions Architect - Associate SAA-C02 topic 1 question 100 discussion

A solutions architect has created two IAM policies: Policy1 and Policy2. Both policies are attached to an IAM group.

A cloud engineer is added as an IAM user to the IAM group. Which action will the cloud engineer be able to perform?

  • A. Deleting IAM users
  • B. Deleting directories
  • C. Deleting Amazon EC2 instances
  • D. Deleting logs from Amazon CloudWatch Logs
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Paitan
Highly Voted 3 years, 8 months ago
The answer is C. There is an explicit DENY on deleting directories in the second policy. So the only thing that can be deleted is EC2 instances as per the permission in the first policy.
upvoted 57 times
...
Karthik_Krishnamoorthy
Highly Voted 3 years, 8 months ago
As per the permission on Policy 1, the Cloud Engineer has full permission for EC2 instances. rest he will have limited permission. iam - Get & List kms - List ec2 - All ds - All (Directory Service) logs - Get & Describe resource - all
upvoted 33 times
noahsark
3 years, 7 months ago
thank you for this. full permission for ec2 and ds. but he was denied for ds in the second policy.
upvoted 7 times
...
...
PhilMultiCloud
Most Recent 3 years, 7 months ago
can someone please help me? I thought DENY overwrites all ALLOWS, so how does DENY ds:delete translate "can only delete EC2"?
upvoted 2 times
astromelon
3 years, 7 months ago
There is an explicit DENY on deleting directories in the second policy.
upvoted 1 times
...
PhilMultiCloud
3 years, 7 months ago
Never mind guys, I was finally able to wrap my head around it lol
upvoted 2 times
...
...
Kenisworld666
3 years, 7 months ago
easy one - C
upvoted 2 times
...
woke
3 years, 7 months ago
C. Deleting Amazon EC2 instances
upvoted 3 times
...
syu31svc
3 years, 7 months ago
C for correct Policy 1 allows all ec2 actions to be taken
upvoted 2 times
...
mryala
3 years, 7 months ago
it's C
upvoted 2 times
...
Ankitrathi85
3 years, 7 months ago
C right
upvoted 2 times
...
Elias23
3 years, 7 months ago
cccccccccc
upvoted 2 times
...
arunchu
3 years, 7 months ago
CCCCCCC
upvoted 2 times
...
anpt
3 years, 8 months ago
CCCCCCCCCCCCCCCCCCCCC
upvoted 5 times
...
venh123
3 years, 8 months ago
It is C
upvoted 2 times
...
lunamycat
3 years, 8 months ago
Yes answer is C.
upvoted 3 times
...
ppptttio89
3 years, 8 months ago
It's in my exam today. I chose the same answer.
upvoted 4 times
...
MFDOOM
3 years, 8 months ago
C. Deleting Amazon EC2 instances
upvoted 3 times
...
peterjohn
3 years, 8 months ago
C is correct
upvoted 2 times
...
charlyAws
3 years, 8 months ago
C is my take
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...