AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard
An IAM user belongs to two groups. One group's policy explicitly denies the s3:DeleteObject action on all resources, while the other group's policy explicitly allows s3:DeleteObject on a specific bucket. When the user attempts to delete an object in that bucket, what is the result?
- AThe action is denied because an explicit deny always overrides any allow
- BThe action is allowed because an explicit allow exists in one policy
- CAWS randomly selects which policy takes precedence
- DThe action is allowed because the user is a member of multiple groups
Show answer & explanationAnswer & explanation
Correct answer: A. The action is denied because an explicit deny always overrides any allow
In IAM policy evaluation, an explicit deny in any applicable policy always overrides any allow, regardless of how many other policies grant the permission. This is a core rule of the IAM policy evaluation logic.
Why the other options are wrong
- B. An explicit deny takes precedence over an allow, so this is incorrect.
- C. Policy evaluation is deterministic, not random.
- D. Group membership doesn't override the explicit deny rule.
IAM Policy Evaluation Logic
When evaluating multiple IAM policies, AWS defaults to implicit deny, but any explicit deny statement always overrides an explicit allow.
- Default is implicit deny (no access unless explicitly allowed)
- Explicit deny in any policy always wins over any allow
- Applies across identity-based and resource-based policies
Memory trick: Deny is the trump card in IAM poker