Courseiva

SCS-C02 Management and Security Governance Practice Question

A company is implementing AWS Organizations with multiple accounts. Which THREE are benefits of using service control policies (SCPs)? (Choose three.)

⚠ Common exam trap

SCS-C02 often tests the misconception that SCPs grant permissions or handle billing, when they only restrict permissions and consolidated billing is a separate Organizations feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prevent users from disabling CloudTrail

Option B is correct because an SCP can deny the cloudtrail:StopLogging and cloudtrail:DeleteTrail actions at the OU or account level, ensuring member accounts cannot disable or delete CloudTrail trails even if their IAM policies allow it. Option C is correct because SCPs let you codify and enforce organizational compliance guardrails—such as blocking use of unapproved regions or services—uniformly across all accounts in an OU. Option E is correct because SCPs are the AWS Organizations mechanism for centrally setting the maximum available permissions for principals in member accounts, restricting what IAM policies can grant. Option A is not a benefit of SCPs because SCPs only filter/limit permissions; they never grant access, so cross-account access must be established with IAM roles, resource policies, or identity federation. Option D is not a benefit of SCPs because consolidated billing is a separate AWS Organizations feature handled by the management account's payment method, not by service control policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Grant cross-account access

    Why it's wrong here

    SCPs are authorization guardrails, not grants: they can only restrict or allow actions that are already available through IAM and resource-based policies, but they never actually create or grant permissions to a principal. Cross-account access is established via IAM roles with trust policies, resource-based policies, or the AWS Organizations delegated administration features, not via SCPs. Therefore, an SCP cannot be used to grant or enable cross-account access.

  • ✓

    Prevent users from disabling CloudTrail

    Why this is correct

    Specifically, SCPs can deny the CloudTrail management actions such as cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail, preventing even the root user in a member account from disabling audit logging. Because SCPs act as an overlay on all IAM identities within the affected accounts, they are an effective detective and preventive control for maintaining an immutable trail record. This is a common pattern for meeting audit and security requirements.

  • ✓

    Enforce compliance requirements

    Why this is correct

    SCPs can enforce compliance by explicitly denying actions that would violate required guardrails, such as stopping CloudTrail, deleting AWS Config recorder, or creating unapproved service resources like public S3 buckets. However, SCPs are based on deny logic; they cannot force a configuration to exist, only block actions that would leave the environment out of compliance. This makes them a practical control to keep the environment within compliance boundaries.

  • ✗

    Manage consolidated billing

    Why it's wrong here

    Consolidated billing is a built-in feature of AWS Organizations that centralizes billing and is managed through the management account's Billing and Cost Management console, not through SCPs. SCPs only affect the permission boundaries for principals within member accounts and have no bearing on billing operations, cost aggregation, or currency conversion. Therefore, using an SCP to manage or alter consolidated billing is not technically correct.

  • ✓

    Centrally restrict permissions across accounts

    Why this is correct

    A central SCP attached to the AWS Organizations root or to an OU applies a common permission boundary to every account beneath it, letting an organization limit allowed actions across those accounts in one place. This centralized restriction is in addition to IAM policies, so the effective permission is the intersection of the SCP boundary and the IAM-based permissions. This is a core design pattern for enforcing a consistent security baseline across multiple accounts.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.