Courseiva

SCS-C02 Management and Security Governance Practice Question

A company needs to centrally manage access to AWS resources across multiple accounts. Which AWS service should be used to define and enforce a set of common permissions for all accounts in the organization?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Organizations with SCPs

AWS Organizations with Service Control Policies (SCPs) allows you to centrally manage and enforce permissions across all accounts in an organization. SCPs define the maximum permissions for accounts and can be applied to the root, OUs, or individual accounts. Option A (AWS Directory Service) is for managed directory services, not for permissions management. Option B (IAM) is per-account and does not centrally manage multiple accounts. Option C (AWS SSO) is for federated access, not for enforcing permissions boundaries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Directory Service

    Why it's wrong here

    AWS Directory Service provides managed Microsoft Active Directory or Simple AD used for identity storage, user authentication, and trust relationships with on-premises directories. It does not contain any mechanism for defining AWS resource permissions; AWS authorization for API calls is handled exclusively by IAM policies and, at the organization level, by SCPs. Directory Service could feed identities into SSO or IAM roles via SAML, but it is not an access-management policy engine for AWS resources.

  • ✗

    AWS IAM

    Why it's wrong here

    AWS IAM is fundamentally account-scoped: IAM users, groups, roles, and policies exist only within a single AWS account and cannot be shared or centrally administered across multiple accounts. Even IAM cross-account roles require pre-existing trust relationships defined per account, and there is no IAM construct that can impose a common, organization-wide permissions baseline. Therefore, while IAM is essential for fine-grained permissions, it is not the tool for central, cross-account access management.

  • ✗

    AWS Single Sign-On (SSO)

    Why it's wrong here

    AWS Single Sign-On (SSO) — now AWS IAM Identity Center — is an identity and access portal that brokers federated sign-in to multiple AWS accounts and business applications. However, the permissions it issues are temporary IAM role sessions scoped to each target account; it does not itself define organization-wide authorization guardrails such as permission boundaries or service control policies. Thus, SSO solves authentication and user-to-account mapping, not the centralized enforcement of common permissions across the entire organization.

  • ✓

    AWS Organizations with SCPs

    Why this is correct

    AWS Organizations with Service Control Policies (SCPs) is the correct mechanism for centrally managing access because SCPs act as organization-wide authorization filters that cap the maximum permissions for every IAM principal—including the root user—in every member account. You can attach SCPs at the root, organizational unit (OU), or account level, and they apply transitively to all child accounts. SCPs do not grant permissions; instead, they explicitly allow or deny API actions, effectively enforcing common compliance guardrails and permission boundaries consistently across the whole organization.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.