Courseiva

SCS-C02 Management and Security Governance Practice Question

A company is using AWS Organizations to manage multiple accounts. The security team wants to prevent any IAM user from creating access keys. Which type of policy should be used to enforce this control across all accounts?

⚠ Common exam trap

SCS-C02 often tests the misconception that IAM permissions boundaries or AWS Config rules can enforce organization-wide preventive controls, when only SCPs provide centralized, preventive permission filtering across all accounts in an OU.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service Control Policy (SCP)

Service Control Policies (SCPs) are the only AWS Organizations policy type that can centrally restrict what IAM principals in member accounts are allowed to do, including denying iam:CreateAccessKey across every account in the OU. Because SCPs set the maximum permissions boundary for all identities in the account, an explicit Deny in an SCP overrides any IAM policy that would otherwise grant the action. This makes SCPs the correct mechanism for enforcing a blanket, organization-wide control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Service Control Policy (SCP)

    Why this is correct

    SCPs are the AWS Organizations feature that centrally controls the maximum allowed permissions for all IAM principals in member accounts. You attach an SCP to the organization root, OUs, or individual accounts, and it applies to every user and role in that account, including the account root user, without requiring per-resource configuration. Because SCPs act as a boundary that IAM policies cannot exceed, they are the effective preventive control to block actions across all accounts in the organization.

  • ✗

    AWS CloudTrail trail

    Why it's wrong here

    A CloudTrail trail records API calls, user activity, and resource events for audit, compliance, and investigation purposes. It is a detective logging service: it captures the fact that an action occurred and who performed it, but it cannot intervene in the request flow, deny an operation, or enforce any authorization policy. Therefore, while it could reveal that a deletion took place, it does not prevent the action from happening.

  • ✗

    AWS Config managed rule

    Why it's wrong here

    An AWS Config managed rule continuously evaluates the configuration of AWS resources against one or more compliance checks, such as requiring MFA on IAM users or flagging public S3 buckets. Config is detective in nature—it reacts to or reports resources that are already noncompliant, and any remediation is either manual or triggered asynchronously after the fact. Because it does not sit in the path of an API call and cannot pre-authorize or deny a request, it is not a preventive control for stopping actions.

  • ✗

    IAM permissions boundary

    Why it's wrong here

    An IAM permissions boundary is a managed policy that defines the maximum permissions an IAM user or role can receive, but it must be explicitly attached to each entity and is managed within a single account. There is no way to apply a single permissions boundary to every principal across all accounts in an organization, and it doesn't affect the account's root user. By contrast, an SCP provides centralized, organization-wide enforcement without per-entity attachment.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.