AWS Solutions Architect Associate (SAA-C03) · Free practice question 1 of 12
IAM explicit deny overrides allow
An IAM user at Larkspur Media belongs to a group with this policy: {"Version": "2012-10-17", "Statement": [{"Effect": "Allow", "Action": "s3:*", "Resource": "arn:aws:s3:::larkspur-reports/*"}]}. The user also has this inline policy: {"Version": "2012-10-17", "Statement": [{"Effect": "Deny", "Action": "s3:DeleteObject", "Resource": "arn:aws:s3:::larkspur-reports/*"}]}. No other policies apply. What happens when the user tries to delete an object in the larkspur-reports bucket?
- A.The request is allowed because the group policy grants s3:*
- B.The request is denied because an explicit Deny overrides any Allow
- C.The request is allowed because group policies take precedence over inline policies
- D.The request is denied only if the bucket has versioning enabled
Show answer and explanation
Correct answer: B. The request is denied because an explicit Deny overrides any Allow
Why: In IAM policy evaluation, an explicit Deny in any applicable policy always overrides an Allow, so the delete is refused even though the group policy allows s3:*. There is no precedence of group policies over inline policies, and versioning does not affect how IAM evaluates the request.
More free AWS Solutions Architect Associate (SAA-C03) questions
- VPC Flow Logs for connectivity troubleshooting
- Transit Gateway instead of peering mesh
- Scheduled scaling for predictable peaks
- RDS point-in-time restore
- Route 53 geolocation routing
- Data Lifecycle Manager for EBS snapshots
- DynamoDB Streams with Lambda
- Amazon MQ for broker migrations
- Graviton instances for price-performance
- Amazon Inspector vulnerability scanning
- Root user protection best practices