AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard

An IAM user belongs to two groups. One group's policy explicitly denies the s3:DeleteObject action on all resources, while the other group's policy explicitly allows s3:DeleteObject on a specific bucket. When the user attempts to delete an object in that bucket, what is the result?

  1. AThe action is denied because an explicit deny always overrides any allow
  2. BThe action is allowed because an explicit allow exists in one policy
  3. CAWS randomly selects which policy takes precedence
  4. DThe action is allowed because the user is a member of multiple groups
Show answer & explanation

Correct answer: A. The action is denied because an explicit deny always overrides any allow

In IAM policy evaluation, an explicit deny in any applicable policy always overrides any allow, regardless of how many other policies grant the permission. This is a core rule of the IAM policy evaluation logic.

Why the other options are wrong

  • B. An explicit deny takes precedence over an allow, so this is incorrect.
  • C. Policy evaluation is deterministic, not random.
  • D. Group membership doesn't override the explicit deny rule.

IAM Policy Evaluation Logic

When evaluating multiple IAM policies, AWS defaults to implicit deny, but any explicit deny statement always overrides an explicit allow.

  • Default is implicit deny (no access unless explicitly allowed)
  • Explicit deny in any policy always wins over any allow
  • Applies across identity-based and resource-based policies

Memory trick: Deny is the trump card in IAM poker

More Security and Compliance questions