AWS CLF-C02 Practice Question
Which AWS service allows you to define granular permissions that allow or deny specific actions on AWS resources
Question
Which AWS service allows you to define granular permissions that allow or deny specific actions on AWS resources?
AIAM policies ✓
BAWS Budgets
CAWS Cost Explorer
DAmazon CloudWatch
Correct Answer: A
IAM policies
Why this is the right answer
Explanation: IAM policies are JSON documents that grant permissions — allowing or denying specific actions on specific resources.
Every AWS Cloud Practitioner question on this site comes from the four official CLF-C02 exam domains. Practice the full domain set in our free timed mock exam and review every topic in the CLF-C02 study guide.
Try this question in the interactive practice test
Start free in seconds — no signup, no credit card. Practice questions, timed mock exams with the official 70% pass threshold, and flashcards.
Related
More Security & Compliance questions
16Under the shared responsibility model, who is responsible for patching the guest operating system of an EC2 instance?17Which AWS service is used to create and manage the encryption keys that protect your data at rest?18Which service records API activity in your AWS account for auditing and governance?19Which service continuously monitors your AWS environment for malicious or unauthorized behavior?20Which AWS service provides a web application firewall to protect applications from common web exploits such as SQL injection?