SCS-C02 Management and Security Governance Practice Question
A company uses AWS Config to evaluate resource compliance. The security team notices that the AWS::IAM::Group resource type is not supported by AWS Config managed rules. What is the best way to detect IAM groups that have an inline policy allowing 'iam:CreateUser'?
⚠ Common exam trap
Candidates often assume AWS Config advanced queries can evaluate any resource type, but AWS Config only supports querying resource types that it records, and IAM groups are not recorded, making Option D ineffective.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom AWS Config rule using a Lambda function that evaluates IAM groups
AWS Config managed rules do not support the AWS::IAM::Group resource type, so you cannot use a managed rule to evaluate inline policies on IAM groups. The best approach is to create a custom AWS Config rule backed by a Lambda function that can evaluate the IAM group's inline policies and trigger a compliance check when the group configuration changes. This allows you to detect any inline policy that contains the 'iam:CreateUser' action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a custom AWS Config rule using a Lambda function that evaluates IAM groups
Why this is correct
AWS Config does not natively record IAM groups, so a Lambda-backed custom rule is required. The Lambda function can call the IAM API to retrieve a group's policies and evaluate them against your compliance logic, then report compliance via PutEvaluations. This approach gives you full flexibility to assess inline and attached managed policies for groups, which no managed Config rule can do.
- ✗
Use IAM Access Analyzer to identify policies that grant broad access
Why it's wrong here
IAM Access Analyzer is designed to identify resources that are shared with external principals by analyzing resource-based policies and role trust policies. It does not scan inline policies attached to IAM groups, nor does it evaluate the overall compliance of group permissions. Therefore it would miss broad access granted inside a group policy and would not produce a compliance verdict for your IAM groups.
- ✗
Use AWS CloudTrail Insights to detect CreateUser events
Why it's wrong here
CloudTrail Insights records unusual API activity patterns, such as anomalous IAM CreateUser or CreateAccessKey calls, but it is an event-detection service. It does not perform static configuration reviews of IAM groups. While it can alert you to suspicious events in real time, it cannot assess whether existing group policies comply with your security standards.
- ✗
Enable AWS Config advanced query and run a query on IAM groups
Why it's wrong here
AWS Config advanced queries run against the resource data that Config records, and IAM groups are not a supported resource type in Config. As a result, a query like 'SELECT ... WHERE resourceType = 'AWS::IAM::Group'' returns no results because Config never captures these resources. Advanced queries are only useful for resources Config actually tracks, such as IAM users or roles, not groups.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.