ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 45 - DVA-C01 discussion

Report
Export

Which of the following are correct statements with policy evaluation logic in AWS Identity and Access Management? Choose 2 answers

A.
By default, all requests are denied
Answers
A.
By default, all requests are denied
B.
An explicit allow overrides an explicit deny
Answers
B.
An explicit allow overrides an explicit deny
C.
An explicit allow overrides default deny.
Answers
C.
An explicit allow overrides default deny.
D.
An explicit deny does not override an explicit allow
Answers
D.
An explicit deny does not override an explicit allow
E.
By default, all request are allowed
Answers
E.
By default, all request are allowed
Suggested answer: A, C

Explanation:

https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.htmlBy default, all requests are implicitly denied. (Alternatively, by default, the AWS account root user has full access.) An explicit allow in an identity- based or resource-based policy overrides this default.

If a permissions boundary, Organizations SCP, or session policy is present, it might override the allow with an implicit deny. An explicit deny in any policy overrides any allows.

asked 16/09/2024
Flamur Kapaj
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first