Courseiva

SAA-C03 Design Secure Architectures Practice Question

A large enterprise uses AWS Organizations to manage multiple accounts. The Chief Information Security Officer (CISO) wants to ensure that no account within the organization can create any resources in regions other than 'us-east-1' and 'us-west-2'. What is the most efficient way to enforce this across the entire organization?

⚠ Common exam trap

SAA-C03 often tests the misconception that IAM policies or Config rules can enforce organization-wide region restrictions, when only SCPs provide preventive, cross-account guardrails.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a Service Control Policy (SCP) to the organization root that denies all actions if the region is not 'us-east-1' or 'us-west-2'.

SCPs are the only AWS Organizations mechanism that centrally enforce permission guardrails across every account in the OU/root, and they apply to all principals including the root user. A deny statement conditioned on aws:RequestedRegion outside us-east-1/us-west-2 blocks resource creation in unauthorized regions before the API call succeeds. Attaching it at the organization root propagates the restriction to every member account with a single policy, which is the most efficient approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an IAM Group in the management account with a region-restrictive policy and add all users to it.

    Why it's wrong here

    IAM Groups are local to a specific AWS account and do not scale across an AWS Organization. Managing users across hundreds of accounts by adding them to a single group in the management account is not feasible and does not prevent root users or new users from creating resources.

  • ✓

    Apply a Service Control Policy (SCP) to the organization root that denies all actions if the region is not 'us-east-1' or 'us-west-2'.

    Why this is correct

    SCPs provide central control over the maximum permissions available for all accounts in your organization. By applying the policy at the root, the restriction is inherited by all member accounts, including the root user of those accounts, ensuring consistent compliance with the CISO's regional requirements.

  • ✗

    Use AWS Config rules in each account to monitor resource creation and delete any resource found in unauthorized regions.

    Why it's wrong here

    AWS Config is a detective control, meaning it identifies violations after they have occurred. While it can trigger remediation actions like deleting resources, it does not prevent the creation of those resources in the first place, which fails to meet the CISO's requirement for proactive enforcement.

  • ✗

    Configure a VPC Endpoint for all services and restrict access to specific regions using VPC Endpoint policies.

    Why it's wrong here

    VPC Endpoint policies control access to services from within a VPC, but they do not prevent users from accessing AWS services through public endpoints or creating resources in other regions via the AWS Console or CLI. This approach is too narrow to enforce a global regional restriction.

About these practice questions

This SAA-C03 question is part of Courseiva's 149-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.