DOP-C02 Security and Compliance Practice Question
Which THREE AWS services can be used to centrally manage and enforce security policies across multiple accounts in AWS Organizations? (Select THREE.)
⚠ Common exam trap
A common mix-up: candidates confuse AWS CloudTrail (audit logging) with a policy enforcement tool, or assume AWS Systems Manager can centrally enforce security policies across accounts, when it is actually designed for operational tasks like patch management and automation, not policy governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Config Conformance Packs
AWS Config Conformance Packs enable you to deploy and enforce a collection of AWS Config rules and remediation actions across multiple accounts and Regions in an AWS Organization. They provide a centralized way to ensure that resources comply with internal policies by using a YAML template that defines the rules and parameters, which are then applied to all member accounts via AWS Config aggregators and StackSets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Config Conformance Packs
Why this is correct
AWS Config Conformance Packs are collections of AWS Config rules and remediation actions that can be deployed across an entire AWS Organization. They enforce compliance by evaluating resource configurations against predefined templates and automatically remediating noncompliant resources. This enables centralized governance of security and operational best practices across all accounts, making them a correct answer for centrally managing compliance.
- ✓
AWS Organizations Service Control Policies (SCPs)
Why this is correct
AWS Organizations Service Control Policies (SCPs) are organization-level policies that centrally control the maximum permissions granted to IAM users and roles in all member accounts. They act as guardrails by restricting which AWS services and actions are allowed, preventing accounts from making unauthorized changes. Because they provide centralized permission governance across accounts, they are a correct answer for central management.
- ✗
AWS Systems Manager
Why it's wrong here
AWS Systems Manager is an operational management service for visibility and control of compute resources, offering capabilities like patch automation, session management, and runbooks. It does not enforce compliance policies across accounts or act as a central policy engine; its focus is on operational tasks at the individual instance or resource level. Therefore, it is not used for central management of account-level policies.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is a logging service that records API activity in each account for audit and governance purposes. It provides visibility into who performed actions and when, but it does not enforce or centrally manage permissions or compliance. Since it is only a detective control rather than a preventive or central governance mechanism, it is incorrect for this question.
- ✓
AWS Firewall Manager
Why this is correct
AWS Firewall Manager is a security management service that centrally configures and applies firewall rules, such as AWS WAF, AWS Shield, and VPC Security Groups, across accounts in an AWS Organization. It simplifies enforcing consistent security policies by automatically aggregating and applying rules to new accounts and resources. This central enforcement capability makes it a correct answer for centrally managing security policies.
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO AWS services can be used to centrally manage and enforce security policies across multiple accounts? (Choose 2.)
easy- A.Amazon S3
- B.Amazon CloudWatch
- ✓ C.AWS Organizations
- ✓ D.AWS Control Tower
- E.AWS Lambda
Why C: AWS Organizations allows you to centrally manage and enforce security policies across multiple accounts by using Service Control Policies (SCPs). SCPs define the maximum permissions for accounts in an organization, enabling you to restrict access to services or actions without requiring per-account configuration. AWS Control Tower provides a managed service that automates the setup of a multi-account environment with pre-built guardrails, which are implemented using SCPs and AWS Config rules to enforce security and compliance policies consistently.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.