Examtopics

AWS Certified Solutions Architect - Associate
  • Topic 1 Question 429

    The following IAM policy is attached to an IAM group. This is the only policy applied to the group.

    What are the effective IAM permissions of this policy for group members?

    • Group members are permitted any Amazon EC2 action within the us-east-1 Region. Statements after the Allow permission are not applied.

    • Group members are denied any Amazon EC2 permissions in the us-east-1 Region unless they are logged in with multi-factor authentication (MFA).

    • Group members are allowed the ec2:StopInstances and ec2:TerminateInstances permissions for all Regions when logged in with multi-factor authentication (MFA). Group members are permitted any other Amazon EC2 action.

    • Group members are allowed the ec2:StopInstances and ec2:TerminateInstances permissions for the us-east-1 Region only when logged in with multi-factor authentication (MFA). Group members are permitted any other Amazon EC2 action within the us-east-1 Region.


    シャッフルモード