CLF-C02 Security and Compliance Practice Question
Which AWS service provides centralized governance and compliance across multiple AWS accounts in an organization?
⚠ Common exam trap
Test-takers frequently confuse AWS Config's compliance evaluation capabilities with centralized governance, but AWS Config is a detective service that reports on compliance after resources are created, whereas AWS Organizations provides preventive governance through SCPs that block non-compliant actions before they occur.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Organizations
AWS Organizations is the correct service because it provides centralized governance and compliance across multiple AWS accounts by enabling you to create a hierarchy of accounts with Service Control Policies (SCPs) that centrally control permissions. SCPs allow you to enforce compliance rules, such as restricting the use of specific AWS services or regions, across all accounts in the organization without requiring individual account-level configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS IAM
Why it's wrong here
AWS IAM grants fine-grained access permissions to individual users, groups, and roles within a single AWS account by using identity-based policies. While IAM roles can be used for cross-account access, IAM itself does not create accounts, structure them into organizational units, or enforce service control policies across an organization. Account-level governance across many accounts is outside IAM's scope.
- ✗
AWS Config
Why it's wrong here
AWS Config is a service that records resource configuration changes, maintains a configuration history, and lets you evaluate compliance against custom or managed rules. It can audit resources across accounts if integrated with Organizations, but it does not provide the centralized account management, service control policy enforcement, or consolidated billing that are core governance functions. It is an assessment tool, not an account governance framework.
- ✓
AWS Organizations
Why this is correct
AWS Organizations is the service that gives centralized governance for multiple AWS accounts, letting you create accounts, group them into organizational units, and apply service control policies that restrict the maximum permissions for all users and roles under those accounts. It also provides consolidated billing, enabling a single payer account to aggregate usage and get volume discounts. This hierarchical, policy-based management is exactly what multi-account governance requires.
- ✗
Amazon Macie
Why it's wrong here
Amazon Macie is a data security service that uses machine learning to discover, classify, and protect sensitive data stored in Amazon S3. It helps identify data exposure or unauthorized access, but it does not govern multiple AWS accounts, manage account hierarchies, or apply policy controls across accounts. Its focus is on data-level protection, not multi-account governance or consolidated billing.
Go deeper
Related to this question
About these practice questions
One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.