SCS-C02 Management and Security Governance Practice Question
A company uses AWS Organizations with all features enabled. The security team wants to ensure that no IAM users are created in any account. Which approach should be used?
⚠ Common exam trap
Many exam-takers confuse IAM policies with SCPs, thinking that an IAM policy attached to the root user can block actions across the account, but SCPs are the only mechanism that can enforce such restrictions across all principals in an organization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach a service control policy (SCP) that denies iam:CreateUser.
Service Control Policies (SCPs) in AWS Organizations allow you to centrally restrict permissions across all accounts in the organization. By attaching an SCP that denies the `iam:CreateUser` action, you prevent the creation of IAM users in any member account, regardless of any IAM policies attached to users or roles within those accounts. This provides a guardrail that cannot be overridden by account administrators, ensuring compliance with the security team's requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS Config rules to detect IAM users and notify via SNS.
Why it's wrong here
AWS Config rules are detective controls: they continuously evaluate resource configurations and can use SNS to notify you when a noncompliant resource, such as a new IAM user, is discovered. However, notifications and even automatic remediation via Systems Manager Automation happen only after the iam:CreateUser call has succeeded, so the action is not prevented. Config also requires enabling recording for IAM resources and does not intercept API requests, making it a reactive mechanism rather than a guardrail.
- ✗
Enable AWS CloudTrail Insights to detect anomalous IAM activity.
Why it's wrong here
AWS CloudTrail Insights is a detective analytics feature that uses machine learning to identify unusual patterns in management events, such as a sudden burst of iam:CreateUser API calls, and then generates findings after the fact. It never inspects or blocks the request path; IAM users can be created before any alert is raised. This is an after-the-fact anomaly detection tool, not a preventive control, so it cannot stop the creation of IAM users as required.
- ✓
Attach a service control policy (SCP) that denies iam:CreateUser.
Why this is correct
A service control policy (SCP) is an organizational policy that specifies the maximum allowed permissions for all principals, including the root user, in every account governed by an AWS Organizations hierarchy. Attaching an SCP that explicitly denies iam:CreateUser to the organization root or a specific OU prevents any principal in those accounts from creating IAM users, regardless of the permissions granted by IAM policies. Because all features are enabled, the SCP is enforced globally across member accounts, making it a true preventive control.
- ✗
Apply an IAM policy to the root user to deny iam:CreateUser.
Why it's wrong here
The AWS account root user is not an IAM identity and cannot have any IAM policies attached to it, so attempting to attach a policy to the root user is invalid. Even if such a policy could be attached, it would only affect the root principal and would not govern other administrators, developers, or roles that might call iam:CreateUser, leaving the control ineffective. Only an SCP at the organization level can restrict the root user and all other principals for member accounts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.