SCS-C02 Infrastructure Security Practice Question
A company uses AWS Organizations with multiple accounts. The security team needs to enforce that all Amazon S3 buckets across the organization are configured to block public access. Which solution should be used to centrally enforce this requirement?
⚠ Common exam trap
Test-takers frequently confuse SCPs with IAM policies or bucket policies, thinking that a bucket policy or an IAM role can centrally enforce a deny across all accounts, but only SCPs operate at the organization level and apply to all principals in the member accounts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a service control policy (SCP) to deny the s3:PutBucketPublicAccessBlock action at the organization root.
Service control policies (SCPs) in AWS Organizations allow you to centrally control the maximum available permissions for all accounts within the organization. By denying the s3:PutBucketPublicAccessBlock action at the organization root, you prevent any account from disabling or modifying the public access block settings on any S3 bucket, thereby enforcing the security team's requirement across all accounts. This approach works because SCPs are applied at the organization level and override any IAM or bucket-level permissions that would otherwise allow the action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AWS Trusted Advisor to automatically remediate public buckets.
Why it's wrong here
AWS Trusted Advisor includes a check that identifies S3 buckets with public read or write access, but it is a diagnostic and advisory service only. It cannot modify bucket policies, enable S3 Block Public Access, or automatically remediate a bucket that is already public. Any response to its findings requires a separate manual or automated action, so it does not provide centralized preventive enforcement.
- ✓
Use a service control policy (SCP) to deny the s3:PutBucketPublicAccessBlock action at the organization root.
Why this is correct
An SCP applied at the organization root in AWS Organizations is an identity-policy boundary that affects every principal, including the root user, in every member account. By explicitly denying the s3:PutBucketPublicAccessBlock action, users cannot create, change, or delete S3 Block Public Access settings, effectively preventing all accounts from removing public-access protections. This is the only option that gives a centrally manageable, organization-wide preventive control.
- ✗
Create an IAM role in each account that denies the s3:PutBucketPublicAccessBlock action.
Why it's wrong here
An IAM role is scoped to a single account, so a role with a deny for s3:PutBucketPublicAccessBlock only applies when a principal assumes that specific role. It does not constrain other IAM users, groups, roles, or the account root, and it must be manually deployed and maintained in every account. Since it cannot bind all accounts and all principals at once, it is not a central enforcement mechanism.
- ✗
Apply a bucket policy to each bucket that blocks public access.
Why it's wrong here
A bucket policy can contain a Deny for s3:PutBucketPublicAccessBlock, but it must be attached individually to each existing bucket and does not automatically apply to any bucket created afterward. It is a resource-based control that leaves coverage gaps whenever a new bucket is added, and nothing prevents account administrators from creating unprotected buckets elsewhere. Without an organization-level guardrail such as an SCP, this is neither comprehensive nor centrally enforceable.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.