SAA-C03 Design Secure Architectures Practice Question
A large enterprise uses AWS Organizations to manage multiple accounts. The Chief Information Security Officer (CISO) wants to ensure that no account within the organization can create any resources in regions other than 'us-east-1' and 'us-west-2'. What is the most efficient way to enforce this across the entire organization?
⚠ Common exam trap
SAA-C03 often tests the misconception that IAM policies or Config rules can enforce organization-wide region restrictions, when only SCPs provide preventive, cross-account guardrails.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a Service Control Policy (SCP) to the organization root that denies all actions if the region is not 'us-east-1' or 'us-west-2'.
SCPs are the only AWS Organizations mechanism that centrally enforce permission guardrails across every account in the OU/root, and they apply to all principals including the root user. A deny statement conditioned on aws:RequestedRegion outside us-east-1/us-west-2 blocks resource creation in unauthorized regions before the API call succeeds. Attaching it at the organization root propagates the restriction to every member account with a single policy, which is the most efficient approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM Group in the management account with a region-restrictive policy and add all users to it.
Why it's wrong here
IAM Groups are local to a specific AWS account and do not scale across an AWS Organization. Managing users across hundreds of accounts by adding them to a single group in the management account is not feasible and does not prevent root users or new users from creating resources.
- ✓
Apply a Service Control Policy (SCP) to the organization root that denies all actions if the region is not 'us-east-1' or 'us-west-2'.
Why this is correct
SCPs provide central control over the maximum permissions available for all accounts in your organization. By applying the policy at the root, the restriction is inherited by all member accounts, including the root user of those accounts, ensuring consistent compliance with the CISO's regional requirements.
- ✗
Use AWS Config rules in each account to monitor resource creation and delete any resource found in unauthorized regions.
Why it's wrong here
AWS Config is a detective control, meaning it identifies violations after they have occurred. While it can trigger remediation actions like deleting resources, it does not prevent the creation of those resources in the first place, which fails to meet the CISO's requirement for proactive enforcement.
- ✗
Configure a VPC Endpoint for all services and restrict access to specific regions using VPC Endpoint policies.
Why it's wrong here
VPC Endpoint policies control access to services from within a VPC, but they do not prevent users from accessing AWS services through public endpoints or creating resources in other regions via the AWS Console or CLI. This approach is too narrow to enforce a global regional restriction.
About these practice questions
This SAA-C03 question is part of Courseiva's 149-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.