Courseiva

Implementing Least Privilege with Emergency Break-Glass Access Across Accounts

A company wants to implement a least-privilege security model across multiple AWS accounts. Which TWO services can help enforce this?

⚠ Common exam trap

Many exam-takers confuse AWS Config (which detects compliance) with a service that enforces policies, or they think KMS or CloudTrail can restrict permissions, when in fact only SCPs and IAM Access Analyzer (for validating policies against least-privilege) directly support enforcing or validating a least-privilege model across multiple accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Organizations Service Control Policies (SCPs)

AWS Organizations Service Control Policies (SCPs) (B) are correct because they set permission guardrails at the organization, OU, or account level, defining the maximum permissions available to IAM principals in member accounts, which directly enforces least privilege across multiple accounts. IAM Access Analyzer (D) is correct because it analyzes resource-based policies and IAM policies to identify resources shared with external entities or unused permissions, generating findings that help teams tighten access to only what is needed. AWS KMS (A) is a key management and encryption service, not a mechanism for enforcing least-privilege access boundaries across accounts. AWS Config (C) evaluates resource configuration compliance but does not itself restrict or grant permissions. AWS CloudTrail (E) provides API activity logging and auditing, which supports detection and investigation rather than enforcement of least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Key Management Service (KMS)

    Why it's wrong here

    KMS manages encryption keys and their access policies; it does not define which AWS API actions an identity may call. It is tempting because KMS is genuinely the right service when the requirement is controlling who can encrypt, decrypt, or rotate specific customer managed keys.

  • ✓

    AWS Organizations Service Control Policies (SCPs)

    Why this is correct

    SCPs set the permissions boundary for every IAM principal in member accounts, so they cap what identity policies can ever grant. This makes them the mechanism for enforcing least privilege centrally across accounts, rather than relying on per-account IAM review.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config evaluates resource configuration against rules and reports drift; it cannot constrain which actions an identity may perform. It is tempting because Config is genuinely the right service when the requirement is detecting and remediating non-compliant resource settings.

  • ✓

    AWS Identity and Access Management (IAM) Access Analyzer

    Why this is correct

    IAM Access Analyzer continuously analyses resource-based policies across accounts, identifying resources shared with external entities to flag unintended access. It satisfies the least-privilege constraint by surfacing overly permissive grants, enabling teams to remediate and tighten policies. Combined with IAM policies, it enforces minimum necessary permissions organisation-wide.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail records API activity for auditing and detection; it does not grant or restrict permissions, so it cannot enforce least privilege. It is tempting because CloudTrail is genuinely the right service when the requirement is capturing an immutable audit trail of who invoked which API.

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.