Courseiva
Security and CompliancemediumMultiple ChoiceObjective-mapped

CLF-C02 Security and Compliance Practice Question

A company is expanding its AWS environment from a single account to multiple accounts using AWS Organizations. The security team wants to enforce a baseline set of permissions across all accounts, ensuring that users in any account cannot disable AWS CloudTrail or modify Amazon S3 bucket policies that prevent public access. Which feature of AWS Organizations should the security team use to achieve this control?

⚠ Common exam trap

Test-takers frequently confuse AWS Config rules (detective) with SCPs (preventive), thinking that Config rules can block actions when they only alert on non-compliance after the fact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Service Control Policies (SCPs)

Service Control Policies (SCPs) are the correct choice because they allow you to centrally define and enforce baseline permissions across all accounts in an AWS Organization. SCPs act as a guardrail, restricting what actions users and roles in member accounts can perform, even if they have full administrative privileges within their own account. By creating an SCP that explicitly denies the `cloudtrail:StopLogging`, `cloudtrail:DeleteTrail`, and `s3:PutBucketPolicy` actions (or similar), the security team can prevent disabling CloudTrail and modifying S3 bucket policies that block public access across the entire organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Consolidated Billing

    Why it's wrong here

    Consolidated Billing simply aggregates invoices and cost data from all linked accounts into a single monthly bill for the management account, and it may offer volume discounts across accounts. However, it operates entirely at the financial layer and has no mechanism to evaluate, deny, or restrict any AWS API actions. It cannot enforce security baselines or prevent any configuration change; it is a billing and cost-management feature, not a security control. Therefore, it does not meet the requirement to enforce permissions across a multi-account environment.

  • Service Control Policies (SCPs)

    Why this is correct

    SCPs allow you to define and enforce maximum permissions for all accounts in your AWS Organization. They act as a guardrail, ensuring that even if an account has permissive IAM policies, the effective permissions are limited by the SCP. This enables central enforcement of security baselines such as preventing the disabling of CloudTrail or modification of S3 bucket policies that block public access.

  • AWS Config rules

    Why it's wrong here

    AWS Config rules evaluate your resource configurations against desired policies. They can detect noncompliant resources and trigger remediation actions, but they do not prevent actions from being taken in real time. They are detective, not preventive, controls.

    When this WOULD be correct

    A company wants to automatically detect and remediate noncompliant S3 bucket policies that allow public access across multiple accounts. AWS Config rules with auto-remediation using AWS Systems Manager Automation would be the correct answer.

  • IAM roles

    Why it's wrong here

    IAM roles grant permissions to users and services within a single AWS account. They cannot centrally restrict permissions across multiple accounts. While cross-account roles exist, they are not designed to enforce a baseline of allowed or denied actions across all accounts in an organization.

    When this WOULD be correct

    A question where a company needs to delegate cross-account access for a specific role, such as allowing a central security team to assume a role in each account to audit CloudTrail configurations, without enforcing a baseline policy across all accounts.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.

Service Control Policies (SCPs)Correct answer

Why this is correct

SCPs allow you to define and enforce maximum permissions for all accounts in your AWS Organization. They act as a guardrail, ensuring that even if an account has permissive IAM policies, the effective permissions are limited by the SCP. This enables central enforcement of security baselines such as preventing the disabling of CloudTrail or modification of S3 bucket policies that block public access.

AWS Config rulesWrong answer — click to see why

Why this is wrong here

AWS Config rules can detect noncompliant configurations but cannot prevent actions; they are detective, not preventive. The question requires enforcing a baseline that prevents users from disabling CloudTrail or modifying S3 bucket policies, which SCPs achieve by denying those actions.

★ When this WOULD be the correct answer

A company wants to automatically detect and remediate noncompliant S3 bucket policies that allow public access across multiple accounts. AWS Config rules with auto-remediation using AWS Systems Manager Automation would be the correct answer.

Why candidates choose this

Candidates may confuse detective controls (AWS Config) with preventive controls (SCPs), especially when the question mentions 'enforce' and 'baseline' — terms that can apply to both detection and prevention.

IAM rolesWrong answer — click to see why

Why this is wrong here

IAM roles grant permissions to users or services within an account but cannot enforce a baseline set of permissions across all accounts in an AWS Organization. They are account-specific and do not provide centralized control to prevent disabling CloudTrail or modifying S3 bucket policies across multiple accounts.

★ When this WOULD be the correct answer

A question where a company needs to delegate cross-account access for a specific role, such as allowing a central security team to assume a role in each account to audit CloudTrail configurations, without enforcing a baseline policy across all accounts.

Why candidates choose this

Candidates may think IAM roles are the primary mechanism for controlling permissions in AWS, overlooking that SCPs operate at the organization level to set permission guardrails across all accounts.

Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 988 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.