Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company uses AWS Organizations to centrally manage multiple AWS accounts. The security team requires a mechanism to prevent any IAM user or role in any member account from modifying Amazon S3 bucket policies to grant public access. The solution must be enforced centrally and cannot be overridden by account administrators. Which AWS feature should the company use?

⚠ Common exam trap

Test-takers frequently confuse SCPs with IAM permissions boundaries, thinking both are equally enforceable centrally, but SCPs operate at the organization level and cannot be bypassed by account administrators, whereas permissions boundaries are account-level and can be removed or modified by an admin with sufficient privileges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Service control policies (SCPs)

Service control policies (SCPs) are the correct choice because they allow AWS Organizations to centrally define permission guardrails that apply to all IAM users and roles across member accounts. SCPs can explicitly deny actions like s3:PutBucketPolicy to prevent any account administrator from modifying S3 bucket policies to grant public access, and these restrictions cannot be overridden by any IAM entity within the member account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IAM permissions boundaries

    Why it's wrong here

    IAM permissions boundaries limit the maximum permissions for an IAM user or role, but they are applied per entity and can be overridden by other policies within the account. They do not provide a centralized guardrail across all member accounts in an organization.

    When this WOULD be correct

    A question that asks for a way to restrict the maximum permissions that a specific IAM user or role can have within a single account, while still allowing account administrators to grant permissions within that boundary. For example: 'A company wants to ensure that developers in a single account cannot create IAM roles with full admin access, but the account admin can manage other permissions.'

  • Service control policies (SCPs)

    Why this is correct

    SCPs are used in AWS Organizations to centrally manage permissions across all accounts. They define the maximum available permissions and can explicitly deny actions like modifying S3 bucket policies. SCPs apply to all principals in the account and cannot be bypassed by account administrators.

  • AWS Config conformance packs

    Why it's wrong here

    AWS Config conformance packs contain a collection of AWS Config rules and remediation actions. They can evaluate resources against policies and trigger remediation, but they do not actively prevent actions; they detect and potentially fix noncompliant resources after the fact.

    When this WOULD be correct

    A company needs to automatically detect and remediate S3 buckets that are publicly accessible across multiple accounts, using AWS Config rules and custom remediation actions via Systems Manager Automation.

  • AWS CloudTrail Insights

    Why it's wrong here

    AWS CloudTrail Insights uses machine learning to analyze management events and detect anomalous API activity, such as unexpected changes to S3 bucket policies, by establishing a baseline of normal behavior. However, it is strictly a detective control: it records and alerts on events after they occur and does not have any capability to evaluate, deny, or block an API call in real time. Since it cannot prevent an account administrator from modifying an S3 bucket policy, it is not a centralized preventive guardrail like an SCP.

    When this WOULD be correct

    A company needs to detect anomalous API activity, such as unusual patterns of S3 bucket policy modifications that might indicate a security threat. CloudTrail Insights would be the correct answer for a question about identifying suspicious behavior rather than enforcing restrictions.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

Service control policies (SCPs)Correct answer

Why this is correct

SCPs are used in AWS Organizations to centrally manage permissions across all accounts. They define the maximum available permissions and can explicitly deny actions like modifying S3 bucket policies. SCPs apply to all principals in the account and cannot be bypassed by account administrators.

IAM permissions boundariesWrong answer — click to see why

Why this is wrong here

IAM permissions boundaries apply to individual IAM users or roles within an account, not across multiple accounts centrally. They can be overridden by account administrators with sufficient permissions, so they do not meet the requirement for a centrally enforced, unoverridable control.

★ When this WOULD be the correct answer

A question that asks for a way to restrict the maximum permissions that a specific IAM user or role can have within a single account, while still allowing account administrators to grant permissions within that boundary. For example: 'A company wants to ensure that developers in a single account cannot create IAM roles with full admin access, but the account admin can manage other permissions.'

Why candidates choose this

Candidates may confuse permissions boundaries with service control policies because both can limit permissions, but they operate at different levels (IAM vs. organization) and have different override capabilities.

AWS Config conformance packsWrong answer — click to see why

Why this is wrong here

AWS Config conformance packs evaluate resource compliance against rules but cannot enforce or prevent actions; they only detect and report non-compliance after the fact.

★ When this WOULD be the correct answer

A company needs to automatically detect and remediate S3 buckets that are publicly accessible across multiple accounts, using AWS Config rules and custom remediation actions via Systems Manager Automation.

Why candidates choose this

Candidates may confuse detection and enforcement, thinking that conformance packs can block actions, or they may overestimate AWS Config's preventive capabilities.

AWS CloudTrail InsightsWrong answer — click to see why

Why this is wrong here

AWS CloudTrail Insights analyzes API call patterns to detect unusual activity, but it cannot prevent or enforce restrictions on S3 bucket policy modifications. It is a detective control, not a preventive one.

★ When this WOULD be the correct answer

A company needs to detect anomalous API activity, such as unusual patterns of S3 bucket policy modifications that might indicate a security threat. CloudTrail Insights would be the correct answer for a question about identifying suspicious behavior rather than enforcing restrictions.

Why candidates choose this

Candidates may confuse CloudTrail Insights with a security enforcement tool because it provides visibility into API usage, but they overlook that it lacks preventive capabilities and cannot centrally block actions across accounts.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CLF-C02 question is part of Courseiva's 988-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.