Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

A company uses AWS Organizations with SCPs to restrict access to services. The security team needs to ensure that no IAM user or role in any account can create or modify VPCs. Which SCP should be applied to the root OU?

⚠ Common exam trap

The trap here is that candidates often focus on only one action (Create or Modify) and forget that both are needed to fully prevent VPC creation and modification, or they mistakenly think an Allow SCP can restrict access when SCPs are primarily used for Deny boundaries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":["ec2:CreateVpc","ec2:ModifyVpc"],"Resource":"*"}]}

It denies both the ec2:CreateVpc and ec2:ModifyVpc actions, which covers all operations that could create or modify VPCs. A service control policy (SCP) with a Deny effect overrides any Allow permissions, ensuring that no IAM user or role in any account under the root OU can perform these actions, even if attached IAM policies grant them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    {"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"ec2:ModifyVpc","Resource":"*"}]}

    Why it's wrong here

    This SCP only denies ec2:ModifyVpc, but does not block ec2:CreateVpc. An account can still run ec2:CreateVpc to provision new VPCs, completely bypassing the intent to prevent VPC creation and modification. In SCP semantics, an explicit deny on one action does not affect other actions, and without a CreateVpc deny, any IAM Allow from other policies can remain effective.

  • ✗

    {"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"ec2:CreateVpc","Resource":"*"}]}

    Why it's wrong here

    This SCP denies only ec2:CreateVpc, leaving ec2:ModifyVpc fully permitted. Consequently, an IAM principal can still alter existing VPCs—such as changing CIDR blocks, DNS settings, or viewing/editing attributes—which is precisely the kind of change the organization wants to prevent. The missing ModifyVpc action in the Deny list means the SCP is incomplete and does not enforce the intended boundary.

  • ✓

    {"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":["ec2:CreateVpc","ec2:ModifyVpc"],"Resource":"*"}]}

    Why this is correct

    This SCP correctly denies both ec2:CreateVpc and ec2:ModifyVpc in a single Deny statement. Because an explicit Deny in an SCP overrides any Allow from IAM policies or other SCPs, this creates a hard boundary that blocks both creation and modification of VPCs across all accounts in the organization. The array format properly lists both actions to ensure complete coverage of the intended restriction.

  • ✗

    {"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["ec2:CreateVpc","ec2:ModifyVpc"],"Resource":"*"}]}

    Why it's wrong here

    Using an Allow effect instead of Deny does not prevent either ec2:CreateVpc or ec2:ModifyVpc; it only lists those actions as permitted. SCPs do not grant real permissions on their own—they require corresponding IAM allows for actual access—but the critical flaw is that this policy does nothing to prohibit VPC operations. The requirement is to restrict certain actions, so a Deny is necessary, and an Allow undermines the security goal by explicitly permitting the very actions that should be blocked.

About these practice questions

One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company uses AWS Organizations with SCPs to restrict access to services. The security team needs to ensure that no IAM user or role can create or modify VPCs, but should allow VPC usage for existing VPCs. Which SCP should be attached to the root OU?

medium
  • A.{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"ec2:CreateVpc","Resource":"*"}]}
  • ✓ B.{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":["ec2:CreateVpc","ec2:ModifyVpc"],"Resource":"*"}]}
  • C.{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":"ec2:*","Resource":"*"}]}
  • D.{"Version":"2012-10-17","Statement":[{"Effect":"Deny","Action":["ec2:CreateVpc","ec2:DeleteVpc"],"Resource":"*"}]}

Why B: The SCP must deny both ec2:CreateVpc and ec2:ModifyVpc to prevent creation and modification of VPCs, while allowing other VPC actions for existing VPCs. Option B includes both actions, which meets the requirement. It does not deny other VPC actions like DescribeVpcs or CreateSubnet, so existing VPCs can still be used.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.