CLF-C02 Security and Compliance Practice Question
A company is expanding its AWS environment from a single account to multiple accounts using AWS Organizations. The security team wants to enforce a baseline set of permissions across all accounts, ensuring that users in any account cannot disable AWS CloudTrail or modify Amazon S3 bucket policies that prevent public access. Which feature of AWS Organizations should the security team use to achieve this control?
⚠ Common exam trap
Test-takers frequently confuse AWS Config rules (detective) with SCPs (preventive), thinking that Config rules can block actions when they only alert on non-compliance after the fact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service Control Policies (SCPs)
Service Control Policies (SCPs) are the correct choice because they allow you to centrally define and enforce baseline permissions across all accounts in an AWS Organization. SCPs act as a guardrail, restricting what actions users and roles in member accounts can perform, even if they have full administrative privileges within their own account. By creating an SCP that explicitly denies the `cloudtrail:StopLogging`, `cloudtrail:DeleteTrail`, and `s3:PutBucketPolicy` actions (or similar), the security team can prevent disabling CloudTrail and modifying S3 bucket policies that block public access across the entire organization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Consolidated Billing
Why it's wrong here
Consolidated Billing simply aggregates invoices and cost data from all linked accounts into a single monthly bill for the management account, and it may offer volume discounts across accounts. However, it operates entirely at the financial layer and has no mechanism to evaluate, deny, or restrict any AWS API actions. It cannot enforce security baselines or prevent any configuration change; it is a billing and cost-management feature, not a security control. Therefore, it does not meet the requirement to enforce permissions across a multi-account environment.
- ✓
Service Control Policies (SCPs)
Why this is correct
SCPs allow you to define and enforce maximum permissions for all accounts in your AWS Organization. They act as a guardrail, ensuring that even if an account has permissive IAM policies, the effective permissions are limited by the SCP. This enables central enforcement of security baselines such as preventing the disabling of CloudTrail or modification of S3 bucket policies that block public access.
- ✗
AWS Config rules
Why it's wrong here
AWS Config rules evaluate your resource configurations against desired policies. They can detect noncompliant resources and trigger remediation actions, but they do not prevent actions from being taken in real time. They are detective, not preventive, controls.
When this WOULD be correct
A company wants to automatically detect and remediate noncompliant S3 bucket policies that allow public access across multiple accounts. AWS Config rules with auto-remediation using AWS Systems Manager Automation would be the correct answer.
- ✗
IAM roles
Why it's wrong here
IAM roles grant permissions to users and services within a single AWS account. They cannot centrally restrict permissions across multiple accounts. While cross-account roles exist, they are not designed to enforce a baseline of allowed or denied actions across all accounts in an organization.
When this WOULD be correct
A question where a company needs to delegate cross-account access for a specific role, such as allowing a central security team to assume a role in each account to audit CloudTrail configurations, without enforcing a baseline policy across all accounts.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓Service Control Policies (SCPs)Correct answer▾
Why this is correct
SCPs allow you to define and enforce maximum permissions for all accounts in your AWS Organization. They act as a guardrail, ensuring that even if an account has permissive IAM policies, the effective permissions are limited by the SCP. This enables central enforcement of security baselines such as preventing the disabling of CloudTrail or modification of S3 bucket policies that block public access.
✗AWS Config rulesWrong answer — click to see why▾
Why this is wrong here
AWS Config rules can detect noncompliant configurations but cannot prevent actions; they are detective, not preventive. The question requires enforcing a baseline that prevents users from disabling CloudTrail or modifying S3 bucket policies, which SCPs achieve by denying those actions.
★ When this WOULD be the correct answer
A company wants to automatically detect and remediate noncompliant S3 bucket policies that allow public access across multiple accounts. AWS Config rules with auto-remediation using AWS Systems Manager Automation would be the correct answer.
Why candidates choose this
Candidates may confuse detective controls (AWS Config) with preventive controls (SCPs), especially when the question mentions 'enforce' and 'baseline' — terms that can apply to both detection and prevention.
✗IAM rolesWrong answer — click to see why▾
Why this is wrong here
IAM roles grant permissions to users or services within an account but cannot enforce a baseline set of permissions across all accounts in an AWS Organization. They are account-specific and do not provide centralized control to prevent disabling CloudTrail or modifying S3 bucket policies across multiple accounts.
★ When this WOULD be the correct answer
A question where a company needs to delegate cross-account access for a specific role, such as allowing a central security team to assume a role in each account to audit CloudTrail configurations, without enforcing a baseline policy across all accounts.
Why candidates choose this
Candidates may think IAM roles are the primary mechanism for controlling permissions in AWS, overlooking that SCPs operate at the organization level to set permission guardrails across all accounts.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.