Courseiva
Security →hardMultiple Choice

DVA-C02 Security Practice Question

A company has a multi-account architecture using AWS Organizations. The security team wants to centrally manage IAM policies that apply to all accounts. Which AWS feature should the developer use?

⚠ Common exam trap

DVA-C02 often tests the misconception that IAM policies or cross-account roles can centrally govern all accounts, when in fact only SCPs in AWS Organizations provide organization-wide permission guardrails.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service control policies (SCPs) in AWS Organizations.

Service control policies (SCPs) in AWS Organizations are the only feature that lets you centrally define and enforce permission guardrails across every account in the organization. SCPs are attached at the OU or account level and define the maximum permissions available to IAM principals in member accounts, so a single policy change propagates to all accounts. This directly satisfies the requirement to 'centrally manage IAM policies that apply to all accounts.'

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Service control policies (SCPs) in AWS Organizations.

    Why this is correct

    Service Control Policies (SCPs) in AWS Organizations are powerful guardrails that define the maximum available permissions for accounts, Organizational Units (OUs), or the entire organization. They do not grant permissions themselves but filter the permissions that IAM policies can grant, effectively restricting actions across all affected accounts centrally. This centralized enforcement mechanism is ideal for establishing and maintaining security and compliance standards across a multi-account architecture, ensuring no account can exceed the defined boundaries.

  • ✗

    IAM cross-account roles.

    Why it's wrong here

    IAM cross-account roles facilitate delegated access by allowing a trusted entity in one AWS account to assume a role in another, granting temporary permissions. While essential for secure inter-account communication and resource access, these roles must be individually configured within each target account, including their trust policies and permissions policies. They enable access *between* accounts but do not provide a centralized, organization-wide mechanism to *restrict* or *enforce* a baseline set of maximum permissions across all accounts simultaneously.

  • ✗

    AWS Config conformance packs.

    Why it's wrong here

    AWS Config conformance packs are collections of AWS Config rules and remediation actions designed to audit and report on the compliance of resources against specified configuration best practices or regulatory standards. They are excellent for assessing whether resources adhere to desired configurations and for identifying non-compliant resources. However, conformance packs focus on evaluating resource configurations and compliance posture, not on directly controlling or enforcing the maximum permissions that users and roles within those accounts can exercise.

  • ✗

    IAM policies attached to the root user.

    Why it's wrong here

    The AWS account root user possesses unrestricted administrative access to all resources within its respective account and is created when an AWS account is first opened. A fundamental security principle dictates that IAM policies, which define permissions for IAM users, groups, and roles, cannot be directly attached to the root user. The root user's permissions are inherent and cannot be modified or restricted by IAM policies, rendering this option ineffective for centrally managing or restricting permissions across an organization.

About these practice questions

This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.