ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A company using AWS IAM creates user accounts without attaching any inline or managed policies directly to the users. Instead, it adds each user to one or more IAM groups that already have the required policies. During an audit, a new developer account is observed launching Amazon EC2 instances even though no policies are linked to that user. Which entitlement concept best explains how the developer received the ability to start instances?
The developer can launch EC2 instances because the IAM policies attached to the group are automatically applied to every member of that group. The user's effective permissions are therefore not the result of a direct assignment but of group membership, demonstrating the concept of inherited rights. Implicit deny is the default lack of permission until an explicit allow is granted. The need-to-know principle concerns limiting access to only what is necessary for a role, and separation of duties involves splitting responsibilities to prevent fraud or error. Neither of those explains how permissions were obtained; only inheritance from the group does.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are AWS IAM Groups?
Open an interactive chat with Bash
What is the concept of inherited rights in IAM?
Open an interactive chat with Bash
How does implicit deny work in AWS IAM?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .