CertKeen

AWS Solutions Architect Associate (SAA-C03) · Free practice question 1 of 12

IAM explicit deny overrides allow

An IAM user at Larkspur Media belongs to a group with this policy: {"Version": "2012-10-17", "Statement": [{"Effect": "Allow", "Action": "s3:*", "Resource": "arn:aws:s3:::larkspur-reports/*"}]}. The user also has this inline policy: {"Version": "2012-10-17", "Statement": [{"Effect": "Deny", "Action": "s3:DeleteObject", "Resource": "arn:aws:s3:::larkspur-reports/*"}]}. No other policies apply. What happens when the user tries to delete an object in the larkspur-reports bucket?

  1. A.The request is allowed because the group policy grants s3:*
  2. B.The request is denied because an explicit Deny overrides any Allow
  3. C.The request is allowed because group policies take precedence over inline policies
  4. D.The request is denied only if the bucket has versioning enabled
Show answer and explanation

Correct answer: B. The request is denied because an explicit Deny overrides any Allow

Why: In IAM policy evaluation, an explicit Deny in any applicable policy always overrides an Allow, so the delete is refused even though the group policy allows s3:*. There is no precedence of group policies over inline policies, and versioning does not affect how IAM evaluates the request.

More free AWS Solutions Architect Associate (SAA-C03) questions