Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 SCPs are a feature of AWS Organizations. Practice Question

A company uses AWS Organizations to manage multiple accounts. The security team wants a preventive control to ensure that nobody in any account, including account root users, can disable AWS CloudTrail or delete Amazon S3 bucket policies. Which AWS feature should the security team use?

⚠ Common exam trap

It's easy for candidates to confuse detective/corrective controls (like AWS Config rules) with preventive controls (like SCPs), or they mistakenly think IAM MFA can block API actions, when in reality MFA only adds an authentication requirement and does not restrict specific service operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Service control policies (SCPs)

Service control policies (SCPs) are the correct choice because they provide centralized preventive controls over the maximum available permissions for all IAM users, roles, and root users in member accounts within AWS Organizations. SCPs can explicitly deny actions such as cloudtrail:StopLogging, cloudtrail:DeleteTrail, and s3:PutBucketPolicy, ensuring that even root users cannot disable CloudTrail or delete S3 bucket policies. This makes SCPs the only AWS feature that can enforce such restrictions across all accounts in an organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IAM roles with multi-factor authentication (MFA)

    Why it's wrong here

    IAM roles with MFA enhance authentication security but do not prevent an administrator within an account from performing destructive actions such as disabling CloudTrail or deleting bucket policies. They control who can assume a role, not what actions are allowed across accounts.

    When this WOULD be correct

    A question asks for a detective or preventive control to require MFA before performing sensitive actions (e.g., stopping an EC2 instance) for specific IAM users or roles.

  • AWS Config rules with automatic remediation

    Why it's wrong here

    AWS Config rules are detective controls that evaluate resources for compliance with desired configurations. While automatic remediation can fix noncompliant resources after they are created, it does not prevent the initial action. For example, it could detect that CloudTrail was disabled and re-enable it, but does not stop the disable action from occurring.

    When this WOULD be correct

    A company wants to automatically detect and remediate noncompliant resource configurations, such as ensuring CloudTrail is enabled or S3 bucket policies are not deleted, after they occur. In that scenario, AWS Config rules with automatic remediation would be the correct answer.

  • Service control policies (SCPs)

    Why this is correct

    SCPs are a feature of AWS Organizations that allow central administrators to set permission guardrails for all accounts in the organization. SCPs can explicitly deny actions like cloudtrail:StopLogging or s3:DeleteBucketPolicy, even for the root user of member accounts. This provides a preventive control that cannot be overridden by account administrators.

  • AWS Shield Advanced

    Why it's wrong here

    AWS Shield Advanced is a managed DDoS protection service designed to safeguard applications from distributed denial-of-service attacks. It does not provide any capabilities for managing or restricting IAM permissions or resource configurations across multiple accounts.

    When this WOULD be correct

    A company wants to protect its AWS resources from distributed denial-of-service (DDoS) attacks and needs enhanced detection, mitigation, and cost protection. AWS Shield Advanced would be the correct answer for such a scenario.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

Service control policies (SCPs)Correct answer

Why this is correct

SCPs are a feature of AWS Organizations that allow central administrators to set permission guardrails for all accounts in the organization. SCPs can explicitly deny actions like cloudtrail:StopLogging or s3:DeleteBucketPolicy, even for the root user of member accounts. This provides a preventive control that cannot be overridden by account administrators.

IAM roles with multi-factor authentication (MFA)Wrong answer — click to see why

Why this is wrong here

IAM roles with MFA control user access but cannot enforce preventive restrictions across all accounts, including root users, in an AWS Organization.

★ When this WOULD be the correct answer

A question asks for a detective or preventive control to require MFA before performing sensitive actions (e.g., stopping an EC2 instance) for specific IAM users or roles.

Why candidates choose this

Candidates may think MFA provides strong security and assume it can prevent all actions, but it does not block root users or apply organization-wide.

AWS Config rules with automatic remediationWrong answer — click to see why

Why this is wrong here

AWS Config rules with automatic remediation are detective and reactive, not preventive. They can detect noncompliant changes and trigger remediation actions, but they cannot prevent root users or others from making changes in the first place.

★ When this WOULD be the correct answer

A company wants to automatically detect and remediate noncompliant resource configurations, such as ensuring CloudTrail is enabled or S3 bucket policies are not deleted, after they occur. In that scenario, AWS Config rules with automatic remediation would be the correct answer.

Why candidates choose this

Candidates may confuse 'preventive' with 'detective and corrective' controls, or think that automatic remediation can block actions before they happen, not realizing it only reacts after the fact.

AWS Shield AdvancedWrong answer — click to see why

Why this is wrong here

AWS Shield Advanced is a DDoS protection service, not a preventive control for restricting actions like disabling CloudTrail or deleting S3 bucket policies across all accounts in an organization.

★ When this WOULD be the correct answer

A company wants to protect its AWS resources from distributed denial-of-service (DDoS) attacks and needs enhanced detection, mitigation, and cost protection. AWS Shield Advanced would be the correct answer for such a scenario.

Why candidates choose this

Candidates may confuse 'preventive control' with 'protection' and think Shield Advanced provides broad security controls, or they may not fully understand the scope of SCPs in AWS Organizations.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CLF-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses AWS Organizations to manage multiple accounts. The security team wants to enforce a policy that prevents any user or role in any member account from disabling AWS CloudTrail or deleting CloudTrail log files from Amazon S3. The team needs a solution that is centrally managed from the management account and applies to all current and future member accounts automatically. Which AWS feature should the security team use to meet these requirements?

medium
  • A.AWS Config conformance packs
  • B.Service Control Policies (SCPs)
  • C.IAM permissions boundaries
  • D.AWS CloudTrail data events

Why B: Service Control Policies (SCPs) are a feature of AWS Organizations that allow you to centrally control the maximum available permissions for all accounts within an organization. By attaching an SCP that explicitly denies the actions to disable CloudTrail or delete CloudTrail log files from S3, the security team can enforce this policy across all current and future member accounts from the management account, as SCPs automatically apply to new accounts added to the organization.

Variation 2. A company is using AWS Organizations to manage multiple AWS accounts. The security team wants to ensure that users in the development accounts cannot disable AWS CloudTrail logging or delete CloudTrail trails, even if those users have full administrator permissions within their own accounts. The team needs a central mechanism that is enforced across all development accounts regardless of individual IAM policies. Which AWS feature should the security team use to meet this requirement?

medium
  • A.Service control policies (SCPs)
  • B.IAM policies
  • C.AWS Config rules
  • D.Amazon CloudWatch Events

Why A: Service control policies (SCPs) are a feature of AWS Organizations that allow you to centrally control the maximum available permissions for all accounts in an organization. SCPs act as a guardrail, restricting what actions users and roles in member accounts can perform, even if they have full administrator permissions via IAM policies. By applying an SCP that denies the `cloudtrail:DeleteTrail` and `cloudtrail:StopLogging` actions, the security team can enforce that CloudTrail cannot be disabled or deleted across all development accounts, regardless of individual IAM configurations.

Variation 3. A company manages multiple AWS accounts under a single AWS Organizations organization. The security team wants to implement a preventive control that blocks any action that would disable AWS CloudTrail or delete CloudTrail log files across all accounts, including the management account. The solution must be centrally managed and must not require changes to individual account permissions. Which AWS feature should the security team use?

medium
  • A.IAM permission boundaries
  • B.AWS Service Control Policies (SCPs)
  • C.AWS Identity and Access Management (IAM) roles with a trust policy
  • D.AWS Config conformance packs

Why B: AWS Service Control Policies (SCPs) apply to all member accounts in an organization, but they explicitly do not apply to the management account. The management account retains full permissions and cannot be restricted by SCPs. Therefore, an SCP cannot block actions in the management account. No other option provides a preventive control across all accounts including the management account without requiring per-account permission changes, making the question invalid as written.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.