Replacing FullAWSAccess with an EC2-only Allow caps the admin roles to EC2 actions and denies everything else

Answer Correct answer: B — EC2 API actions remain allowed for the administrative roles, while every other API action is denied.

A company uses AWS Organizations to manage its AWS accounts. The organization root has a child OU that is named Department. The Department OU has a child OU that is named Engineering. The default FullAWSAccess policy is attached to the root, the Department OU, and the Engineering OU. The company has many AWS accounts in the Engineering OU. Each account has an administrative IAM role with the AdministratorAccess IAM policy attached. The default FullAWSAccessPolicy is also attached to each account. A DevOps engineer plans to remove the FullAWSAccess policy from the Department OU. The DevOps engineer will replace the policy with a policy that contains an Allow statement for all Amazon EC2 API operations. What will happen to the permissions of the administrative 1AM roles as a result of this change?

  1. All API actions on all resources will be allowed.
  2. All API actions on EC2 resources will be allowed. All other API actions will be denied. Correct Answer
  3. All API actions on all resources will be denied.
  4. All API actions on EC2 resources will be denied. All other API actions will be allowed.

Community Votes

B
77%
A
23%

77% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

SCP evaluation is an intersection across all levels, not a union, and the Department OU's policy becomes a stricter ceiling for everything beneath it (B). The AdministratorAccess managed policy on each administrative role cannot restore permissions because an SCP deny or a restrictive allow boundary caps identity-based policies. aws_god's argument that FullAWSAccess remains attached to the Engineering OU and therefore preserves access is incorrect: an allow at a lower level can only narrow the permissions granted by parents, never widen what the parent allows, so the Engineering OU's FullAWSAccess becomes irrelevant once the Department OU restricts the ceiling to EC2.

Service control policies are evaluated at every level of the organization hierarchy, and an account's effective permissions are the intersection of what every policy from the root down to the account permits. Removing FullAWSAccess from the Department OU and attaching a policy that only Allows EC2 API operations therefore caps every account beneath it, including all the Engineering OU accounts whose administrative roles hold AdministratorAccess. Because no policy above the Department OU allows anything beyond EC2, the administrative roles retain EC2 access but every non-EC2 API action is denied.

Reasoning that all API actions remain allowed because FullAWSAccess is still attached to the Engineering OU and to each account (the A argument) — this inverts how SCP evaluation works. An SCP allow lower in the hierarchy cannot grant permissions that a policy above it does not permit; the effective permission set is the intersection, so the Department OU's EC2-only policy becomes the binding constraint for every account and role beneath it. hzaki and teo2157 both cited the AWS documentation on SCP evaluation to reach the correct conclusion.

Community Discussion (6 comments)

teo2157 👍 2 Selected: B
It's B based on this url https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_evaluation.html
aws_god 👍 2 Selected: A
The default FullAWSAccess policy is attached to the root, the Department OU, and the Engineering OU. So even if it is removed from the Department OU, it is still attached on the Engineering OU.
ApacheKafkaAWS 👍 2 Selected: B
I'ts B
siheom 👍 2 Selected: B
vote B..
hzaki 👍 4 Selected: B
When the FullAWSAccess policy is replaced with a policy that allows only EC2 actions, this new SCP will act as a boundary. Even if an IAM role or user within the account has a broader permission set (like AdministratorAccess), the SCP limits what can be done.
hzaki 👍 1 Selected: A
The answer is A Still, the root has attached a full access policy.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AWS Organizations evaluates service control policies hierarchically, and the effective permissions of a principal are the logical intersection of the identity-based policies that apply and the permissions allowed by every SCP attached at each level of the organization path. When FullAWSAccess is removed from the Department OU and replaced with a policy whose only statement is an Allow for Amazon EC2 API operations, that policy imposes a ceiling on every account and OU below it. The accounts in the Engineering OU, whose administrative roles carry the AdministratorAccess managed policy, therefore keep their EC2 permissions but lose every other API action, because the intersection with the Department OU's EC2-only allow cannot include any non-EC2 action. aws_god's reading, that FullAWSAccess on the Engineering OU keeps permissions wide, misunderstands the direction of the intersection: an allow at a child level can only narrow what its parents permit, never expand it.

Why the Other Options Are Wrong

A claims all API actions on all resources will be allowed, on the theory that FullAWSAccess is still attached to the Engineering OU and to each account. That reasoning treats SCPs as if a lower-level allow could grant permissions independently of its parents, which is the opposite of how evaluation works; the Engineering OU's FullAWSAccess can only add permissions that the Department OU's policy already forbids. C claims all API actions on all resources will be denied, which would be the outcome if the replacement policy contained no Allow for EC2. Because the new policy explicitly allows EC2 API operations, EC2 access is retained. D claims EC2 is denied and everything else allowed, which inverts the actual result. B is correct.

Community Comment Notes

Community voted B (77), with A a 23 percent minority. teo2157, ApacheKafkaAWS, siheom, and hzaki all cited the AWS documentation on SCP evaluation to support B, with hzaki explaining that the new SCP acts as a boundary that overrides broader permissions granted by identity-based policies like AdministratorAccess. The minority position was aws_god's, based on FullAWSAccess still being attached at the Engineering OU.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide