Courseiva

SCS-C02 Management and Security Governance Practice Question

A company has multiple AWS accounts managed through AWS Organizations. The security team needs to ensure that no EC2 instances are launched without an approved Amazon Machine Image (AMI). Which governance control should be implemented?

⚠ Common exam trap

Many candidates confuse IAM policies with SCPs, assuming that an IAM policy can enforce organization-wide controls, but SCPs are the only mechanism that applies as a permission boundary across all accounts in an AWS Organization and cannot be overridden by account administrators.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a service control policy (SCP) that denies ec2:RunInstances unless the AMI ID is in an approved list.

A service control policy (SCP) is the correct governance control because it operates at the AWS Organizations level, allowing the security team to enforce a deny on ec2:RunInstances across all member accounts unless the AMI ID matches an approved list. SCPs are account permission boundaries that cannot be overridden by IAM policies within the account, ensuring that no user or role can launch an EC2 instance with an unapproved AMI, even if they have full administrative privileges. This provides a preventive control that blocks non-compliant actions before they occur, which is more robust than detective or reactive measures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a service control policy (SCP) that denies ec2:RunInstances unless the AMI ID is in an approved list.

    Why this is correct

    A service control policy (SCP) is the correct preventive control because it applies at the AWS Organizations level and acts as a permission boundary that no IAM principal in a member account can bypass, including account administrators. By adding a Deny statement for ec2:RunInstances with a condition such as ec2:ImageId not being in the approved AMI list (using StringNotEquals or ForAnyValue:StringNotEquals), the restriction is enforced before any EC2 instance is launched. SCPs do not grant permissions, but they effectively block non-compliant launches across all accounts and future accounts.

  • ✗

    Deploy an AWS Config rule that triggers a Lambda function to terminate non-compliant instances.

    Why it's wrong here

    An AWS Config rule coupled with a Lambda function is a reactive, post-launch remediation mechanism rather than a preventive control. The rule only detects that a running instance is using an unapproved AMI after the ec2:RunInstances call has already succeeded, so the unauthorized instance exists and may process data or incur cost before Lambda terminates it. This approach also depends on the Lambda function having sufficient IAM permissions and on the Config rule being properly scoped, and it does not stop the API action itself.

  • ✗

    Use AWS CloudTrail to monitor instance launches and alert the security team.

    Why it's wrong here

    CloudTrail is a detective and auditing service that records API activity after the fact; it cannot evaluate or block an ec2:RunInstances request at the time it is made. Using CloudTrail to monitor launches and alert the security team requires a human to notice and respond to the alarm, leaving a significant window during which the non-compliant instance remains active. It provides visibility for forensic analysis but does not enforce an approved-AMI policy, so it is not a preventive control in any meaningful sense.

  • ✗

    Use an IAM policy that restricts ec2:RunInstances to approved AMIs.

    Why it's wrong here

    An IAM policy restricting ec2:RunInstances to approved AMIs is not organization-wide and must be attached to every user, group, or role in every account, which is error-prone and hard to maintain. More importantly, an account administrator with IAM permissions can create, modify, or detach IAM policies, potentially bypassing the restriction. The condition key ec2:ImageId can be used in IAM, but this approach lacks the central guardrail enforcement that an SCP provides and does not prevent an admin from granting themselves broader access.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.