CLF-C02 SCPs are a feature of AWS Organizations. Practice Question
A company uses AWS Organizations to manage multiple accounts. The security team wants a preventive control to ensure that nobody in any account, including account root users, can disable AWS CloudTrail or delete Amazon S3 bucket policies. Which AWS feature should the security team use?
⚠ Common exam trap
It's easy for candidates to confuse detective/corrective controls (like AWS Config rules) with preventive controls (like SCPs), or they mistakenly think IAM MFA can block API actions, when in reality MFA only adds an authentication requirement and does not restrict specific service operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service control policies (SCPs)
Service control policies (SCPs) are the correct choice because they provide centralized preventive controls over the maximum available permissions for all IAM users, roles, and root users in member accounts within AWS Organizations. SCPs can explicitly deny actions such as cloudtrail:StopLogging, cloudtrail:DeleteTrail, and s3:PutBucketPolicy, ensuring that even root users cannot disable CloudTrail or delete S3 bucket policies. This makes SCPs the only AWS feature that can enforce such restrictions across all accounts in an organization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IAM roles with multi-factor authentication (MFA)
Why it's wrong here
IAM roles with MFA enhance authentication security but do not prevent an administrator within an account from performing destructive actions such as disabling CloudTrail or deleting bucket policies. They control who can assume a role, not what actions are allowed across accounts.
When this WOULD be correct
A question asks for a detective or preventive control to require MFA before performing sensitive actions (e.g., stopping an EC2 instance) for specific IAM users or roles.
- ✗
AWS Config rules with automatic remediation
Why it's wrong here
AWS Config rules are detective controls that evaluate resources for compliance with desired configurations. While automatic remediation can fix noncompliant resources after they are created, it does not prevent the initial action. For example, it could detect that CloudTrail was disabled and re-enable it, but does not stop the disable action from occurring.
When this WOULD be correct
A company wants to automatically detect and remediate noncompliant resource configurations, such as ensuring CloudTrail is enabled or S3 bucket policies are not deleted, after they occur. In that scenario, AWS Config rules with automatic remediation would be the correct answer.
- ✓
Service control policies (SCPs)
Why this is correct
SCPs are a feature of AWS Organizations that allow central administrators to set permission guardrails for all accounts in the organization. SCPs can explicitly deny actions like cloudtrail:StopLogging or s3:DeleteBucketPolicy, even for the root user of member accounts. This provides a preventive control that cannot be overridden by account administrators.
- ✗
AWS Shield Advanced
Why it's wrong here
AWS Shield Advanced is a managed DDoS protection service designed to safeguard applications from distributed denial-of-service attacks. It does not provide any capabilities for managing or restricting IAM permissions or resource configurations across multiple accounts.
When this WOULD be correct
A company wants to protect its AWS resources from distributed denial-of-service (DDoS) attacks and needs enhanced detection, mitigation, and cost protection. AWS Shield Advanced would be the correct answer for such a scenario.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓Service control policies (SCPs)Correct answer▾
Why this is correct
SCPs are a feature of AWS Organizations that allow central administrators to set permission guardrails for all accounts in the organization. SCPs can explicitly deny actions like cloudtrail:StopLogging or s3:DeleteBucketPolicy, even for the root user of member accounts. This provides a preventive control that cannot be overridden by account administrators.
✗IAM roles with multi-factor authentication (MFA)Wrong answer — click to see why▾
Why this is wrong here
IAM roles with MFA control user access but cannot enforce preventive restrictions across all accounts, including root users, in an AWS Organization.
★ When this WOULD be the correct answer
A question asks for a detective or preventive control to require MFA before performing sensitive actions (e.g., stopping an EC2 instance) for specific IAM users or roles.
Why candidates choose this
Candidates may think MFA provides strong security and assume it can prevent all actions, but it does not block root users or apply organization-wide.
✗AWS Config rules with automatic remediationWrong answer — click to see why▾
Why this is wrong here
AWS Config rules with automatic remediation are detective and reactive, not preventive. They can detect noncompliant changes and trigger remediation actions, but they cannot prevent root users or others from making changes in the first place.
★ When this WOULD be the correct answer
A company wants to automatically detect and remediate noncompliant resource configurations, such as ensuring CloudTrail is enabled or S3 bucket policies are not deleted, after they occur. In that scenario, AWS Config rules with automatic remediation would be the correct answer.
Why candidates choose this
Candidates may confuse 'preventive' with 'detective and corrective' controls, or think that automatic remediation can block actions before they happen, not realizing it only reacts after the fact.
✗AWS Shield AdvancedWrong answer — click to see why▾
Why this is wrong here
AWS Shield Advanced is a DDoS protection service, not a preventive control for restricting actions like disabling CloudTrail or deleting S3 bucket policies across all accounts in an organization.
★ When this WOULD be the correct answer
A company wants to protect its AWS resources from distributed denial-of-service (DDoS) attacks and needs enhanced detection, mitigation, and cost protection. AWS Shield Advanced would be the correct answer for such a scenario.
Why candidates choose this
Candidates may confuse 'preventive control' with 'protection' and think Shield Advanced provides broad security controls, or they may not fully understand the scope of SCPs in AWS Organizations.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CLF-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses AWS Organizations to manage multiple accounts. The security team wants to enforce a policy that prevents any user or role in any member account from disabling AWS CloudTrail or deleting CloudTrail log files from Amazon S3. The team needs a solution that is centrally managed from the management account and applies to all current and future member accounts automatically. Which AWS feature should the security team use to meet these requirements?
medium- A.AWS Config conformance packs
- ✓ B.Service Control Policies (SCPs)
- C.IAM permissions boundaries
- D.AWS CloudTrail data events
Why B: Service Control Policies (SCPs) are a feature of AWS Organizations that allow you to centrally control the maximum available permissions for all accounts within an organization. By attaching an SCP that explicitly denies the actions to disable CloudTrail or delete CloudTrail log files from S3, the security team can enforce this policy across all current and future member accounts from the management account, as SCPs automatically apply to new accounts added to the organization.
Variation 2. A company is using AWS Organizations to manage multiple AWS accounts. The security team wants to ensure that users in the development accounts cannot disable AWS CloudTrail logging or delete CloudTrail trails, even if those users have full administrator permissions within their own accounts. The team needs a central mechanism that is enforced across all development accounts regardless of individual IAM policies. Which AWS feature should the security team use to meet this requirement?
medium- ✓ A.Service control policies (SCPs)
- B.IAM policies
- C.AWS Config rules
- D.Amazon CloudWatch Events
Why A: Service control policies (SCPs) are a feature of AWS Organizations that allow you to centrally control the maximum available permissions for all accounts in an organization. SCPs act as a guardrail, restricting what actions users and roles in member accounts can perform, even if they have full administrator permissions via IAM policies. By applying an SCP that denies the `cloudtrail:DeleteTrail` and `cloudtrail:StopLogging` actions, the security team can enforce that CloudTrail cannot be disabled or deleted across all development accounts, regardless of individual IAM configurations.
Variation 3. A company manages multiple AWS accounts under a single AWS Organizations organization. The security team wants to implement a preventive control that blocks any action that would disable AWS CloudTrail or delete CloudTrail log files across all accounts, including the management account. The solution must be centrally managed and must not require changes to individual account permissions. Which AWS feature should the security team use?
medium- A.IAM permission boundaries
- ✓ B.AWS Service Control Policies (SCPs)
- C.AWS Identity and Access Management (IAM) roles with a trust policy
- D.AWS Config conformance packs
Why B: AWS Service Control Policies (SCPs) apply to all member accounts in an organization, but they explicitly do not apply to the management account. The management account retains full permissions and cannot be restricted by SCPs. Therefore, an SCP cannot block actions in the management account. No other option provides a preventive control across all accounts including the management account without requiring per-account permission changes, making the question invalid as written.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.