IAM Policy Evaluation Logic Quiz
Quiz covering IAM Policies
IAM Policy Evaluation Logic Quiz
5 questions | Pass: 70% | Earn 25 points
Questions in this quiz
A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.
- 1
In AWS IAM, what is the default behavior if there is no explicit allow and no explicit deny for a request?
- 2
If an IAM policy contains an explicit 'Allow' and a Service Control Policy (SCP) contains an explicit 'Deny' for the same action, what is the final result?
- 3
When evaluating multiple policies attached to an IAM user, which of the following is true regarding the evaluation logic?
- 4
An IAM user has an identity-based policy that allows 's3:ListBucket'. A resource-based policy on a specific S3 bucket denies 's3:ListBucket' to that user. What happens when the user tries to list that bucket?
- 5
A developer is troubleshooting an access issue. The user has an identity-based policy with 'Allow' for 'ec2:DescribeInstances'. There is a Permission Boundary attached to the user that does not include 'ec2:DescribeInstances'. What is the result?
- Amazon GuardDuty Configuration
- Amazon GuardDuty Configuration Quiz5q
- GuardDuty Runtime Monitoring
- GuardDuty Runtime Monitoring Quiz5q
- Security Hub Aggregation
- Security Hub Aggregation Quiz5q
- AWS Security Finding Format (ASFF)
- AWS Security Finding Format (ASFF) Quiz5q
- Amazon Inspector Scanning
- Amazon Inspector Scanning Quiz5q
Enjoying the courses?
Everything stays free. Pro shows fewer ads, doubles the points you earn on every lesson and quiz so you progress twice as fast, unlocks half of every practice exam — plus full case studies — with the Learn & Exam study modes, and lets you read each lesson on one page.
- ✓ Fewer advertisements
- ✓ 2× points per lesson & quiz
- ✓ 50% of every exam unlocked
- ✓ Learn & Exam modes
- ✓ Distraction-free lessons