DOP-C02 Security and Compliance Practice Question
Which TWO AWS services can be used to centrally manage and enforce security policies across multiple accounts? (Choose 2.)
⚠ Common exam trap
Test-takers frequently confuse AWS Organizations with AWS Control Tower, thinking they are mutually exclusive, but Control Tower actually builds on Organizations to provide a higher-level managed governance solution, making both correct for central policy enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Organizations
AWS Organizations allows you to centrally manage and enforce security policies across multiple accounts by using Service Control Policies (SCPs). SCPs define the maximum permissions for accounts in an organization, enabling you to restrict access to services or actions without requiring per-account configuration. AWS Control Tower provides a managed service that automates the setup of a multi-account environment with pre-built guardrails, which are implemented using SCPs and AWS Config rules to enforce security and compliance policies consistently.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon S3
Why it's wrong here
Amazon S3 is an object storage service, not a policy management service. While S3 bucket policies can control access to objects within a single bucket, they cannot be applied across accounts or used as central governance mechanisms. S3 may serve as a central log destination for AWS CloudTrail and other audit data, but storing logs does not equate to managing or enforcing policies across an organization.
- ✗
Amazon CloudWatch
Why it's wrong here
Amazon CloudWatch is a monitoring and observability service used to collect metrics, logs, and events, and to set alarms for operational health. It can detect non-compliant resource changes via CloudTrail integration and trigger automated remediation with Lambda, but it does not define, apply, or centrally administer access policies. CloudWatch insights and log analytics are diagnostic tools, not governance guards, so it cannot serve as a central policy management service.
- ✓
AWS Organizations
Why this is correct
AWS Organizations provides central management of multiple AWS accounts through hierarchical grouping into organizational units (OUs). It enables the creation and enforcement of service control policies (SCPs), which act as guardrails to restrict the maximum permissions of IAM roles and users across member accounts. SCPs can be attached to the root, OUs, or individual accounts, giving centralized, policy-based control over an entire enterprise environment.
- ✓
AWS Control Tower
Why this is correct
AWS Control Tower offers automated governance and compliance enforcement by building a landing zone on top of AWS Organizations. Control Tower provides pre-packaged guardrails—both preventive (using SCPs) and detective (using AWS Config rules)—that are automatically deployed across accounts and OUs. It centralizes management through a dedicated dashboard, making it a valid choice for centrally managing policy guardrails across a multi-account environment at scale.
- ✗
AWS Lambda
Why it's wrong here
AWS Lambda is a serverless compute service that executes code in response to events, such as changes in S3 objects or API calls. Lambda functions can be used to automate remediation of non-compliant resources or to enforce custom logic, but Lambda itself does not manage IAM policies or service control policies. It is a tool for executing actions, not a central governance service for defining and applying policies across accounts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DOP-C02 question from scratch — 1,298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.