Courseiva

SCS-C02 Management and Security Governance Practice Question

A company is using AWS Organizations and wants to restrict the use of specific AWS services in member accounts. Which TWO approaches can be used to enforce these restrictions? (Choose TWO.)

⚠ Common exam trap

SCS-C02 often tests service restriction methods, and candidates may select Service Quotas or CloudTrail, which do not enforce restrictions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a service control policy (SCP) to the organizational unit (OU).

Option C is correct because service control policies (SCPs) in AWS Organizations define the maximum available permissions for accounts in an OU, and an SCP that denies access to specific AWS services will block those services for all principals in the affected member accounts (except the management account). Option D is correct because IAM policies attached to users, groups, or roles in each member account can include explicit Deny statements for the actions of the services to be restricted, thereby enforcing the restriction at the identity level within that account. Option A is not correct because Service Quotas only cap the quantity of resources or API rates per service; they do not block the use of a service. Option B is not correct because AWS CloudTrail only records API activity for auditing and does not enforce any restriction. Option E is not correct because AWS Config rules evaluate and report on resource compliance; they detect and can trigger remediation, but they do not themselves prevent or terminate service usage as an enforcement mechanism.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Service Quotas to limit the number of resources per service.

    Why it's wrong here

    Service Quotas (formerly Service Limits) set account-level maximums for resource counts, such as 5,000 EC2 instances per Region, but they do not deny or restrict specific API actions. A quota is a soft or hard numeric cap on resource inventory, not a permission or policy mechanism. Moreover, quotas can be increased via a support request and are not designed to enforce service usage boundaries across an AWS Organization, so they are not an appropriate tool for restricting service usage.

  • ✗

    Enable AWS CloudTrail to log service usage.

    Why it's wrong here

    AWS CloudTrail is an auditing and governance service that records API activity in the account, producing a log of who made which calls, when, and from where. It is inherently detective, not preventive: enabling CloudTrail does not stop or block any service from being used. Even with Data Events enabled and insights, CloudTrail only provides visibility and evidence for post-hoc analysis, so it fails the requirement to restrict service usage proactively.

  • ✓

    Apply a service control policy (SCP) to the organizational unit (OU).

    Why this is correct

    Applying an SCP to the OU is the correct preventive control at the AWS Organizations level. An SCP can explicitly deny actions for all AWS services or specific services (e.g., ec2:*) across every member account under that OU, and it applies to all IAM principals including the root user. SCPs operate at the account boundary as an allowlist or denylist, and effective permissions are the intersection of the SCP and the IAM identity/resource policies, ensuring that a centrally defined deny cannot be bypassed by per-account IAM policies.

  • ✓

    Create IAM policies in each member account to deny access to the services.

    Why this is correct

    Creating IAM policies in each member account to deny access would only restrict IAM users, groups, and roles that are evaluated by those identity policies; the root user in each member account cannot be constrained by an IAM policy. Additionally, service principals and AWS service-linked roles may not be covered by all such policies, and managing identical deny policies in many accounts creates drift and an inconsistent security posture. This approach also lacks central enforcement—any account administrator able to modify IAM policies could remove the denial, making it far less reliable than an organization-level SCP.

  • ✗

    Use AWS Config rules to automatically terminate resources.

    Why it's wrong here

    AWS Config rules assess whether resources conform to desired configurations and can trigger remediation actions, such as terminating resources, but this is a reactive control. A Config rule only detects and responds after a resource has already been created or a service has already been used, leaving a window where unauthorized usage exists. Config cannot natively prevent an API call from succeeding; it is not an authorization engine, so it fails the requirement to restrict services from being used in the first place.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.