Implementing Least Privilege with Emergency Break-Glass Access Across Accounts
A company wants to implement a least-privilege security model across multiple AWS accounts. Which TWO services can help enforce this?
⚠ Common exam trap
Many exam-takers confuse AWS Config (which detects compliance) with a service that enforces policies, or they think KMS or CloudTrail can restrict permissions, when in fact only SCPs and IAM Access Analyzer (for validating policies against least-privilege) directly support enforcing or validating a least-privilege model across multiple accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Organizations Service Control Policies (SCPs)
AWS Organizations Service Control Policies (SCPs) (B) are correct because they set permission guardrails at the organization, OU, or account level, defining the maximum permissions available to IAM principals in member accounts, which directly enforces least privilege across multiple accounts. IAM Access Analyzer (D) is correct because it analyzes resource-based policies and IAM policies to identify resources shared with external entities or unused permissions, generating findings that help teams tighten access to only what is needed. AWS KMS (A) is a key management and encryption service, not a mechanism for enforcing least-privilege access boundaries across accounts. AWS Config (C) evaluates resource configuration compliance but does not itself restrict or grant permissions. AWS CloudTrail (E) provides API activity logging and auditing, which supports detection and investigation rather than enforcement of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Key Management Service (KMS)
Why it's wrong here
KMS manages encryption keys and their access policies; it does not define which AWS API actions an identity may call. It is tempting because KMS is genuinely the right service when the requirement is controlling who can encrypt, decrypt, or rotate specific customer managed keys.
- ✓
AWS Organizations Service Control Policies (SCPs)
Why this is correct
SCPs set the permissions boundary for every IAM principal in member accounts, so they cap what identity policies can ever grant. This makes them the mechanism for enforcing least privilege centrally across accounts, rather than relying on per-account IAM review.
- ✗
AWS Config
Why it's wrong here
AWS Config evaluates resource configuration against rules and reports drift; it cannot constrain which actions an identity may perform. It is tempting because Config is genuinely the right service when the requirement is detecting and remediating non-compliant resource settings.
- ✓
AWS Identity and Access Management (IAM) Access Analyzer
Why this is correct
IAM Access Analyzer continuously analyses resource-based policies across accounts, identifying resources shared with external entities to flag unintended access. It satisfies the least-privilege constraint by surfacing overly permissive grants, enabling teams to remediate and tighten policies. Combined with IAM policies, it enforces minimum necessary permissions organisation-wide.
- ✗
AWS CloudTrail
Why it's wrong here
CloudTrail records API activity for auditing and detection; it does not grant or restrict permissions, so it cannot enforce least privilege. It is tempting because CloudTrail is genuinely the right service when the requirement is capturing an immutable audit trail of who invoked which API.
Go deeper
Related to this question
About these practice questions
One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.