Which of the following are not possible to do with IAM policies and permissions? (Choose two.)
A. Remove access for a user from EC2 instances.
B. Remove access for the root user from EC2 instances.
C. Give the root user access to a hosted web application.
D. Add an additional user with access to all EC2 instances.