An IAM user has a policy attached (policy contents not shown). Which of the following specific actions would be permitted for that IAM user?
Choose an answer
Tap an option to check your answer.
Correct answer: Amazon EC2 DescribeInstances in the us-east-1 Region.
Why this is the answer
The correct answer is Amazon EC2 DescribeInstances in the us-east-1 Region. Without seeing the policy, the only action that is almost universally permitted for any IAM user, even with minimal permissions, is DescribeInstances or other Describe actions. These actions are read-only and provide information about resources, posing no security risk. Therefore, they are often allowed by default or included in very restrictive policies to enable basic console navigation. Incorrect options: Amazon RDS DescribeDBInstances in the us-east-1 Region: While a Describe action, it pertains to RDS, which might not be included in a user's policy. Amazon S3 PutObject into a bucket named testbucket: PutObject is a write action and requires explicit permission for the specific S3 bucket, making it highly unlikely to be permitted without a tailored policy. Amazon EC2 AttachNetworkInterface in the eu-west-1 Region: AttachNetworkInterface is a modifying action and typically requires explicit permissions, especially across different regions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed