SAA-C03 Practice Question: SCPs set the maximum permissions for all…
A company uses AWS Organizations and wants to prevent any account in the organization from launching resources in regions other than us-east-1 and eu-west-1. This restriction must apply even if an administrator in a member account grants full IAM permissions. Which approach should a solutions architect use?
⚠ Common exam trap
A common misconception is that an IAM Administrator or root user in a member account can override organization-level controls. SCPs define the permission ceiling — even AdministratorAccess (Action: *, Resource: *) cannot exceed what the SCP allows. SCPs are evaluated BEFORE account-level IAM policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an SCP with a Deny on all actions for regions outside us-east-1 and eu-west-1, attached to the Organization root
Service Control Policies (SCPs) in AWS Organizations provide a guardrail that applies to all principals in member accounts — including IAM users, roles, and even the account root. SCPs restrict the maximum permissions that can be granted within an account. An SCP with Deny on all actions for all regions except us-east-1 and eu-west-1, attached to the organization root, prevents any account from launching resources in other regions regardless of account-level IAM permissions. IAM policies in member accounts cannot override SCPs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create IAM policies with Deny for disallowed regions and attach them to all IAM users and roles in each account
Why it's wrong here
IAM policies are resource- and account-scoped; they only apply within a single AWS account and can be overridden by an account administrator who has IAM permissions. To enforce a region restriction across an entire organization, you would need to attach a Deny policy to every IAM user, group, and role in every member account, which is operationally unscalable and leaves gaps for any principal not covered. More importantly, IAM policies are not organization-wide controls — they are subject to the account's own administrative permissions, so a rogue admin can detach or modify them, whereas an SCP attached to the Organization root cannot be bypassed by anyone inside a member account.
- ✗
Enable AWS Config rules to detect resources launched in disallowed regions and trigger auto-remediation to delete them
Why it's wrong here
AWS Config rules are detective, not preventive, controls. A Config rule can only identify resources that already exist in a disallowed region and trigger a remediation action after the fact, meaning the resource has already been created and may have incurred cost or exposed data. This is fundamentally reactive — it does not block the API call that launches the resource in the first place. An SCP, by contrast, is an explicit deny that takes effect at the time of the request, preventing any action in a disallowed region before it can occur.
- ✗
Use AWS Control Tower guardrails to enforce region restriction for all accounts
Why it's wrong here
AWS Control Tower guardrails are built on top of SCPs, but they are a higher-level governance wrapper that requires setting up a landing zone and managing accounts through Control Tower. While a mandatory guardrail could eventually produce an SCP with region restrictions, the guardrail's scope and behavior depend on Control Tower's pre-defined controls, which are not as direct or granular as authoring a custom SCP yourself. For this question, the correct mechanism is to create the SCP and attach it to the Organization root, not to rely on Control Tower's opinionated guardrail framework.
- ✓
Create an SCP with a Deny on all actions for regions outside us-east-1 and eu-west-1, attached to the Organization root
Why this is correct
SCPs apply to all principals in all member accounts and cannot be overridden by account-level IAM. Attached to the Organization root, this SCP covers every member account. The Deny with StringNotEquals condition on aws:RequestedRegion blocks all other regions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.