Courseiva

SCS-C02 Management and Security Governance Practice Question

A company uses AWS Organizations and wants to restrict the AWS Regions in which resources can be created across all member accounts. Which mechanism should be used?

⚠ Common exam trap

SCS-C02 often tests the use of SCPs for centralized governance. Candidates might choose IAM policies or Config rules, but SCPs are the only mechanism that can enforce restrictions across all accounts in an organization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a service control policy (SCP) that denies operations in unauthorized regions.

A service control policy (SCP) in AWS Organizations can be used to restrict the AWS Regions in which resources can be created across all member accounts. SCPs define the maximum permissions for accounts and can deny actions in unauthorized regions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Apply a service control policy (SCP) that denies operations in unauthorized regions.

    Why this is correct

    A service control policy (SCP) attached at the organization root or an organizational unit acts as an upper boundary on all IAM principals in every member account, including the account root user. Because member account administrators cannot modify or remove an SCP, adding a Deny statement with a condition such as aws:RequestedRegion not in an allowed list prevents any operation in unauthorized Regions before the API call executes. This is the recommended preventive, centralized control for enforcing regional boundaries across AWS Organizations.

  • ✗

    Use VPC endpoints to restrict API calls to specific regions.

    Why it's wrong here

    VPC endpoints are Regional network constructs that let a VPC privately connect to a specific AWS service in one Region, but they do not block a caller from targeting a different Regional endpoint using normal AWS SDK, CLI, or console traffic. An endpoint policy only affects requests that traverse that endpoint and cannot stop requests that use the public endpoint or that are made from outside the VPC. Thus VPC endpoints are insufficient as a standalone Amazon-wide restriction because they address the network path, not the authorization scope of the API call.

  • ✗

    Configure AWS Config rules to detect and delete resources in unauthorized regions.

    Why it's wrong here

    AWS Config rules are detective, not preventive: they evaluate the configuration of resources after the resource exists or after an API call has been recorded. Even with automatic remediation, such as SSM automation to delete noncompliant resources, there is a delay during which the unauthorized resource can exist, and Config never blocks the original Create or RunInstances call. Therefore, Config rules cannot enforce a hard prohibition on operating in unauthorized Regions.

  • ✗

    Attach an IAM policy to each user that denies operations in unauthorized regions.

    Why it's wrong here

    Attaching a deny policy to each IAM user provides no organization-wide guarantee because it does not apply to service roles, cross-account roles, or the member account root user, and it can be modified or removed by an administrator who has IAM permissions in that account. In AWS Organizations, only an SCP is protected from being overridden by the member account's own administrators; IAM policies are ultimately under the control of the account administrator. This makes the IAM-only approach an incomplete and unenforceable preventive control.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.