AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceEasy

A new IAM user is created with no attached policies. The user attempts to list objects in an Amazon S3 bucket. What is the outcome of this request?

  1. AThe request succeeds because S3 buckets are publicly readable unless configured otherwise
  2. BThe request succeeds because new IAM users have read-only access by default
  3. CThe request is denied because IAM follows an implicit deny by default unless a policy explicitly allows the action
  4. DThe request is denied only if a Service Control Policy blocks it, otherwise it is allowed
Show answer & explanation

Correct answer: C. The request is denied because IAM follows an implicit deny by default unless a policy explicitly allows the action

IAM uses a default-deny model: unless a policy explicitly grants permission for an action, the request is denied. A user with no attached policies has no allow statements, so every action is implicitly denied.

Why the other options are wrong

  • A. S3 buckets are private by default and this describes S3, not IAM permissions
  • B. IAM users have no permissions by default, not read-only access
  • D. SCPs set maximum boundaries but are irrelevant here since there is no allow at all

Implicit Deny

In IAM, all requests are denied by default unless explicitly allowed by an attached policy.

  • Default state for every IAM principal is deny-all
  • An explicit Deny always overrides an explicit Allow
  • Users need at least one Allow statement to perform any action

Memory trick: No key, no door — IAM locks everything until you hand out a key.

More Security and Compliance questions