20+ practice questions focused on Management and Security Governance — one of the most tested topics on the AWS Certified Security Specialty SCS-C02 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Management and Security Governance PracticeA company is using AWS Organizations with multiple accounts. The security team wants to ensure that all S3 buckets across all accounts are encrypted with AWS KMS. Which policy should be used to enforce this?
Explanation: Service Control Policies (SCPs) at the root OU can deny the s3:PutBucketEncryption action unless the request includes encryption settings that use AWS KMS. This enforces encryption at the organizational level, overriding any account-level permissions, and ensures that all S3 buckets across all accounts are encrypted with KMS.
A startup uses a single AWS account for development. The developer has full administrative access and accidentally deleted an S3 bucket containing critical data. The security team wants to prevent similar incidents without hindering agility. What is the MOST effective control?
Explanation: Enabling S3 Versioning preserves all object versions, allowing recovery of deleted objects, while MFA Delete requires multi-factor authentication to permanently delete object versions or suspend versioning. This prevents accidental or unauthorized permanent deletions without hindering the developer's ability to create, read, and update objects, thus balancing security and agility.
A large enterprise uses AWS Organizations with hundreds of accounts. The security team needs to enforce that all accounts have AWS CloudTrail enabled and logs are delivered to a centralized S3 bucket in the management account. The team also wants to ensure that no account can disable CloudTrail or delete the bucket. Which combination of controls meets these requirements?
Explanation: Service control policies (SCPs) are the correct mechanism because they allow the management account to centrally restrict permissions across all accounts in the organization. By creating an SCP that denies the `cloudtrail:StopLogging`, `cloudtrail:DeleteTrail`, `cloudtrail:UpdateTrail`, and `s3:DeleteBucket` actions, the security team can prevent any account (including root users) from disabling CloudTrail or deleting the centralized S3 bucket, regardless of IAM policies or direct resource-based policies.
A global e-commerce company operates in three AWS Regions: us-east-1, eu-west-1, and ap-southeast-1. The company uses AWS Organizations with 50 member accounts grouped by business unit. The security team recently discovered that several S3 buckets containing customer data were accidentally made public due to misconfigured bucket policies. The team wants to implement a preventive control that blocks any S3 bucket from becoming public across all accounts, while still allowing authorized cross-account access. The solution must be centrally managed and not require changes to existing IAM policies. Additionally, the team needs to be notified immediately when a public bucket is attempted. Which solution meets all requirements?
Explanation: It uses an SCP to centrally deny the s3:PutBucketPolicy and s3:PutBucketAcl actions when the request would make a bucket public, which is a preventive control that blocks the operation before it happens. The requirement for immediate notification is met by using CloudTrail to log the denied API calls and CloudWatch Events to trigger alerts, all without modifying existing IAM policies or requiring per-account changes.
A security engineer is designing a centralized logging solution for a multi-account AWS environment. They need to ensure log files are tamper-proof and cannot be deleted or modified by anyone, including the root user of any account. Which configuration meets these requirements?
Explanation: S3 Object Lock in Compliance mode prevents any user, including the root user, from deleting or overwriting objects until the retention period expires. By storing the logs in a separate account that manages the retention settings, the security engineer ensures that even if an attacker compromises the source account, they cannot modify or delete the logs because the lock is enforced by the destination account's S3 configuration.
+15 more Management and Security Governance questions available
Practice all Management and Security Governance questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Management and Security Governance. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Management and Security Governance questions on the SCS-C02 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Management and Security Governance is tested as part of the AWS Certified Security Specialty SCS-C02 blueprint. Practicing with targeted Management and Security Governance questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SCS-C02 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Management and Security Governance is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Management and Security Governance practice session with instant scoring and detailed explanations.
Start Management and Security Governance Practice →