AWS CLF-C02 Practice Question

Which AWS service allows you to define granular permissions that allow or deny specific actions on AWS resources

Domain: Security & Compliance Question 33 of 60 Free practice

Question

Which AWS service allows you to define granular permissions that allow or deny specific actions on AWS resources?

AIAM policies ✓
BAWS Budgets
CAWS Cost Explorer
DAmazon CloudWatch
Correct Answer: A

IAM policies

Why this is the right answer

Explanation: IAM policies are JSON documents that grant permissions — allowing or denying specific actions on specific resources.
📌 Exam tip: In Security questions, read the "who does what" clues carefully. If the scenario mentions your company managing something, the answer points to the CUSTOMER side of the shared responsibility model; if AWS handles it transparently, it is AWS's responsibility.

Every AWS Cloud Practitioner question on this site comes from the four official CLF-C02 exam domains. Practice the full domain set in our free timed mock exam and review every topic in the CLF-C02 study guide.

Last updated 2026-08-15 · Reviewed by the BestHelpTool certification team · Official exam details: AWS Certified Cloud Practitioner

Try this question in the interactive practice test

Start free in seconds — no signup, no credit card. Practice questions, timed mock exams with the official 70% pass threshold, and flashcards.