Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company is designing a new AWS account structure using AWS Organizations. The security team wants to restrict the use of specific AWS services across all member accounts. Which feature should they use?

⚠ Common exam trap

Candidates often confuse SCPs with IAM policies, thinking IAM cross-account roles can enforce service restrictions, but SCPs are the only mechanism that applies globally across all users and roles in an AWS Organization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service control policies (SCPs)

Service control policies (SCPs) are the correct feature because they allow you to centrally restrict which AWS services and actions are permitted across all member accounts in an AWS Organization. SCPs act as a permission guardrail that applies to all IAM users, roles, and root users within the affected accounts, enabling the security team to enforce service restrictions without modifying individual account configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Single Sign-On (SSO)

    Why it's wrong here

    AWS IAM Identity Center (formerly AWS Single Sign-On) centralizes authentication and user access across multiple AWS accounts and business applications. It allows administrators to define permission sets that map users or groups to IAM roles, but it never intervenes in the account's service request path. SSO is an identity boundary, not an organizational service boundary; a user who gets a role still could access any service permitted by that role and any SCPs.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail is a reporting and governance service that captures an immutable history of API calls made by principals and services in your accounts, including the request parameters and the responding service. It is a detective control that helps you audit activity after the fact, but it does not intercept, evaluate, or deny a request before the operation executes. Therefore, CloudTrail cannot enforce restrictions on which AWS services may be used in a member account; at best, it can reveal that an unauthorized service was used.

  • ✗

    AWS Identity and Access Management (IAM) cross-account roles

    Why it's wrong here

    IAM cross-account roles enable a user or service in one AWS account to assume a security context with permissions defined in another account, typically used to access shared resources without sharing long-term credentials. While the trust policy restricts which external principals can assume the role, and the role's permissions determine what that role may do, this mechanism does not impose a boundary on all IAM principals in the target account. It cannot prevent a local account admin from creating a new unconstrained role or from directly using services the organization wants to ban.

  • ✓

    Service control policies (SCPs)

    Why this is correct

    Service control policies (SCPs) are an AWS Organizations feature that specify the maximum permission boundary for all IAM entities in the accounts, OUs, or root to which they are attached. By adding an SCP that denies or allows specific services, you can prevent member-account users and roots from using services outside the approved set, even if they have IAM policies that allow those actions. SCPs inherit down the organizational hierarchy and are evaluated as a top-level guardrail, making them the appropriate tool to restrict how teams use AWS services in a new account structure.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.