DOP-C02 Service Control Policy (SCP) Practice Question
A company has a multi-account AWS environment using AWS Organizations. The security team has implemented a service control policy (SCP) that denies the creation of IAM users and roles with full admin access. The SCP is attached to all accounts. However, a DevOps engineer in a member account reports that they are able to create an IAM role with an administrator access policy attached. The engineer uses the AWS Management Console to create the role. The SCP is confirmed to be in place. What is the most likely reason the SCP is not preventing the role creation?
⚠ Common exam trap
Candidates often assume that an SCP denying creation of IAM users automatically covers roles, or that SCPs block all administrative actions. In this case, the SCP only prevents user creation, not role creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SCP only denies iam:CreateUser, but the engineer is creating a role (iam:CreateRole).
The SCP in question denies only the iam:CreateUser action, but the engineer is creating an IAM role, which requires the iam:CreateRole action. SCPs provide an explicit deny for actions they list; they do not block actions they do not list. Since the SCP does not deny iam:CreateRole, the engineer's IAM policy (which allows iam:CreateRole) is effective. SCPs are inherited by member accounts and, when correctly attached, cannot be overridden by IAM policies; however, they only apply to the actions they explicitly specify.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SCPs are not inherited by member accounts from the root.
Why it's wrong here
Service control policies are inherited from the organization root through each organizational unit to all member accounts, unless explicitly overridden or blocked. Therefore, if an SCP is attached at the root, every account beneath it is subject to that policy. The claim that SCPs are not inherited by member accounts from the root is false, because AWS Organizations applies SCPs hierarchically to the entire organization.
- ✗
The SCP is not attached to the member account's root organizational unit.
Why it's wrong here
The statement incorrectly assumes that the SCP must be attached to a 'root organizational unit' of the member account. In AWS Organizations, the root is the top-level container for all OUs and accounts; member accounts reside in OUs, and the SCP can be attached to any OU in the account's path or directly to the account itself. Since the question states the SCP is attached to all accounts, it would apply regardless of whether it is attached to a specific OU or the organization root.
- ✗
The engineer's IAM policy allows iam:CreateRole and overrides the SCP.
Why it's wrong here
SCPs are account-level permissions boundaries that define the maximum permissions for all IAM principals in an account; they do not grant any permissions and cannot be overridden by an IAM policy. If an SCP denies an action, the effective permission for that action is always denied, regardless of an allow in an IAM policy. Therefore, an IAM policy allowing iam:CreateRole cannot override an SCP that explicitly denies it, so this option is not a valid explanation for why the create role succeeded.
- ✓
The SCP only denies iam:CreateUser, but the engineer is creating a role (iam:CreateRole).
Why this is correct
The SCP only denies the iam:CreateUser action, which means it does not restrict the engineer's ability to create IAM roles. IAM role creation is governed by the iam:CreateRole permission, which is not covered by the SCP's deny statement. As a result, the engineer can create a new administrative role, attach a permissive policy to it, and assume that role to bypass the intended restrictions and achieve privilege escalation.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.