SCS-C03 Security Foundations and Governance Practice Question
A company wants to implement a robust governance framework for their AWS accounts using AWS Control Tower. They need to ensure that specific security guardrails are applied to their 'Financial-Apps' Organizational Unit (OU). Which TWO types of guardrails can be applied within Control Tower?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preventive guardrails using Service Control Policies (SCPs).
AWS Control Tower provides two types of guardrails: preventive and detective. Preventive guardrails are implemented using Service Control Policies (SCPs) to block unauthorized actions. Detective guardrails are implemented using AWS Config rules to monitor and alert on non-compliant resource configurations. Together, they provide a comprehensive governance layer for managing account compliance and security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Preventive guardrails using Service Control Policies (SCPs).
Why this is correct
Preventive guardrails in Control Tower use SCPs to enforce policies by preventing actions that violate compliance. For example, a preventive guardrail might stop users from deleting log archives or changing critical network settings. These are enforced at the organization level and cannot be bypassed by local account administrators.
- ✓
Detective guardrails using AWS Config rules.
Why this is correct
Detective guardrails continuously monitor the configuration of AWS resources. They use AWS Config to identify resources that deviate from the established security baseline, such as an unencrypted S3 bucket. When a violation occurs, the non-compliance is flagged in the Control Tower dashboard for remediation.
- ✗
Reactive guardrails using AWS Systems Manager Automation documents.
Why it's wrong here
While Systems Manager can be used for remediation, Control Tower does not categorize guardrails as 'reactive' within its native framework. It focuses on prevention and detection. Automation for remediation is typically a secondary step that the customer configures using findings from the detective guardrails provided by the service.
- ✗
Proactive guardrails using IAM Permission Boundaries.
Why it's wrong here
Control Tower does not use IAM Permission Boundaries as a standard guardrail mechanism. Permission boundaries are managed at the IAM level within individual accounts. Control Tower’s primary governance tools are SCPs for prevention and Config rules for detection, which provide broader and more centralized control than boundaries.
- ✗
Administrative guardrails using AWS IAM Identity Center (Succeeded AWS SSO).
Why it's wrong here
While Control Tower integrates with IAM Identity Center for identity management and access control, the guardrails themselves are technically defined as preventive (SCPs) or detective (Config). IAM Identity Center is the mechanism for providing access to the accounts, but it is not a 'guardrail type' within the service's governance model.
About these practice questions
Courseiva writes every SCS-C03 question from scratch — 99 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C03 exam.