SCS-C02 Management and Security Governance Practice Question
A company uses AWS Organizations with multiple accounts. The security team wants to centrally manage IAM policies across all accounts. Which AWS feature should the team use to enforce permissions across member accounts?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service Control Policies (SCPs)
Service Control Policies (SCPs) allow central control over permissions for all accounts in an organization. Option A is wrong because IAM roles with cross-account access provide temporary access but do not enforce policies centrally. Option C is wrong because AWS Config rules are for compliance monitoring, not permission enforcement. Option D is wrong because AWS CloudTrail is for auditing, not enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IAM roles with cross-account access
Why it's wrong here
IAM roles with cross-account access are defined per AWS account and require an explicit trust policy referencing a principal in another account. While you can automate role creation across accounts, roles themselves are not centrally managed or enforced by AWS Organizations—each account must maintain its own role definitions, making this a distributed, account-by-account approach rather than a central governance mechanism like SCPs.
- ✓
Service Control Policies (SCPs)
Why this is correct
Service Control Policies (SCPs) are AWS Organizations policies that centrally manage the maximum available permissions for identities and resources in member accounts. They act as guardrails that restrict what IAM users, roles, and even the root user can do in an account, without granting any permissions themselves. By attaching SCPs to accounts or organizational units, you can enforce consistent permission boundaries across the entire organization, which directly matches the requirement for central permission control.
- ✗
AWS Config rules
Why it's wrong here
AWS Config rules evaluate resource configurations against desired policies and report noncompliant resources, but they do not enforce or deny permissions at the API-call level. Config is fundamentally a detective control—it can flag violations and even trigger automated remediation actions, but it operates after the resource state changes and cannot prevent an unauthorized action from being attempted. To centrally limit permissions before they are exercised, you need a preventive control such as SCPs, not a monitoring tool.
- ✗
AWS CloudTrail trails
Why it's wrong here
AWS CloudTrail trails record API activity for auditing, governance, and forensic analysis, logging who made a call, when, and from where. However, CloudTrail itself never inspects or denies an API request; it is an after-the-fact audit log that exists outside the authorization path. While centralizing trails across accounts helps visibility, it offers zero enforcement capability, making it an ineffective mechanism for centrally managing or restricting permissions across accounts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.