SCS-C02 Management and Security Governance Practice Question
A company uses AWS Organizations and wants to restrict the use of specific AWS services in member accounts. For example, they want to block the use of Amazon Redshift. Which policy type should be used?
⚠ Common exam trap
The trap is confusing SCPs with IAM policies; SCPs are specifically for Organizations and apply across accounts, while IAM policies are within a single account.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service control policies (SCPs)
Service control policies (SCPs) are used in AWS Organizations to centrally manage permissions across multiple accounts. They can restrict which AWS services and actions are available to member accounts. To block the use of Amazon Redshift in member accounts, an SCP can be applied to the organizational units or accounts that denies the redshift:* actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Service control policies (SCPs)
Why this is correct
Service control policies (SCPs) are the correct mechanism because AWS Organizations lets you attach them to the root, OUs, or individual accounts, where they act as an account-wide permission guardrail. An SCP defines the maximum allowed actions for every IAM principal in the account, including the root user, so it can deny entire AWS services across all enrolled accounts. This central, inherited control does not require touching each IAM role or user individually.
- ✗
IAM permissions boundaries
Why it's wrong here
IAM permissions boundaries are wrong here because they are an advanced IAM feature that applies only to a specific IAM user or role, not to an entire AWS account or all accounts in an organization. A permissions boundary can limit that one identity's maximum permissions, but it must be attached to each principal individually and it cannot cross organizational boundaries. Therefore, it cannot restrict service usage across every account in an AWS Organization.
- ✗
IAM identity-based policies
Why it's wrong here
IAM identity-based policies are wrong because they are attached to a single IAM user, group, or role and define what that one identity can do in its own account. They have no visibility into or control over other accounts, and they cannot be attached at the organizational or account level in AWS Organizations. Using them to restrict a service across all accounts would require creating and maintaining identical policies on every principal, which is not an account-wide or organization-wide control.
- ✗
S3 bucket policies
Why it's wrong here
S3 bucket policies are wrong because they are resource-based policies that only control access to a specific S3 bucket or bucket resource, identified by an Amazon Resource Name (ARN). They are scoped to S3 data-plane or control-plane actions on that bucket and cannot affect other services like EC2 or Lambda, nor can they restrict services across an entire organization. A bucket policy is a single-resource guardrail, not a service-wide or account-wide control.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.