SCS-C02 Service Control Policy (SCP) Condition Keys Practice Question
A company runs a critical application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application processes financial transactions and must store transaction logs in an Amazon S3 bucket. The security team requires that all API calls to AWS services are logged and that the logs are stored in a secure, tamper-proof manner. The team enables AWS CloudTrail to log management events and Amazon S3 server access logs for the S3 bucket. They also enable AWS Config to track resource changes. The compliance team wants to ensure that no one can disable CloudTrail logging or delete the CloudTrail log files. The security engineer proposes a solution using an SCP in AWS Organizations to deny actions that would disable CloudTrail or delete log files. However, the engineer is concerned that the SCP might be applied too broadly and affect legitimate administrative actions. The engineer wants to ensure that only the security team’s IAM role (SecurityAdminRole) can perform these restricted actions, while all other principals (including IAM users, roles, and the root user) are denied. The engineer creates an SCP that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and s3:DeleteObject on the CloudTrail S3 bucket. The SCP includes a condition that allows the action if the principal is SecurityAdminRole. However, after applying the SCP, the security team finds that even SecurityAdminRole is unable to stop CloudTrail logging. What is the most likely cause of this issue?
⚠ Common exam trap
SCS-C02 often tests the subtlety that SCP Deny statements with misconfigured principal conditions block everyone, including the intended exempt role — candidates forget that assumed-role ARNs differ from role ARNs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The condition in the SCP is incorrectly scoped, causing the deny to apply to all principals including SecurityAdminRole.
The SCP's condition is likely misconfigured — for example, using a StringNotEquals on aws:PrincipalArn without accounting for the role's assumed-role ARN format, or placing the condition on the wrong element — causing the Deny to apply to all principals including SecurityAdminRole. SCPs are evaluated as a union of allows and an intersection of denies, so a mis-scoped Deny overrides any Allow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The condition in the SCP is incorrectly scoped, causing the deny to apply to all principals including SecurityAdminRole.
Why this is correct
A service control policy (SCP) acts as a permission boundary for all IAM principals in an AWS account. In this scenario, the SCP's condition was written with incorrect scoping—it likely used a condition key that did not match the SecurityAdminRole's principal ARN, or failed to include an exclusion for that role—so the explicit deny in the SCP applied to every principal, including SecurityAdminRole. Because an explicit deny in an SCP overrides any allow from an identity-based policy, the role's IAM permission to call cloudtrail:StopLogging was ineffective, leaving the deny intact and blocking the stop action.
- ✗
The SCP is applied to the root organizational unit (OU), which includes the management account where the root user is not affected by SCPs.
Why it's wrong here
Although SCPs are inherited by all accounts in an organizational unit, they do not apply to the management account's root user—however, that fact does not explain this failure. The SecurityAdminRole is an IAM principal in a member account, where SCPs absolutely apply. Even if the SCP were applied at the root OU and included the management account, the deny would still block the member-account role's stop-logging call; the root user's immunity is irrelevant to the role's inability to act.
- ✗
The SecurityAdminRole does not have the necessary IAM permissions to stop CloudTrail logging.
Why it's wrong here
The SecurityAdminRole already has the required IAM permissions—the engineer attached an identity-based policy allowing cloudtrail:StopLogging—so the problem is not a missing IAM permission. IAM permissions only allow an action if no explicit deny exists; SCPs act as an outer boundary that can effectively revoke those permissions. Since the role's IAM policy is correctly configured, the only remaining reason for the denial is the mis-scoped SCP condition, making this option an incorrect diagnosis.
- ✗
The S3 bucket policy on the CloudTrail bucket denies access to the SecurityAdminRole.
Why it's wrong here
An S3 bucket policy governs access to the bucket objects, but stopping CloudTrail logging is an API call to cloudtrail:StopLogging, not an S3 operation. Even if a bucket policy denied the role access to the log bucket, that would not prevent the CloudTrail API action—it would only block reading or deleting the objects. The issue here is an SCP condition, not a resource-based policy, so a bucket-policy denial cannot be the root cause of the failure.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.