Courseiva

SCS-C02 Identity and Access Management Practice Question

A company uses AWS Organizations with SCPs. The SCP for the production OU denies all actions on DynamoDB. An IAM policy attached to a user in that OU allows dynamodb:PutItem. What is the effective access?

⚠ Common exam trap

The trap is assuming that an IAM Allow can override an SCP Deny—candidates must remember that SCPs are guardrails and explicit denies in SCPs always win over IAM allows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The user cannot perform PutItem because the SCP denies all DynamoDB actions and IAM allows are overridden.

In AWS Organizations, Service Control Policies (SCPs) define the maximum permissions for accounts in an OU. An explicit Deny in an SCP overrides any Allow in IAM policies. Since the SCP denies all DynamoDB actions, the user cannot perform PutItem regardless of the IAM policy allowing it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user can perform PutItem because the IAM policy allows it.

    Why it's wrong here

    The user's IAM policy may indeed permit PutItem, but an SCP acts as an upper boundary on permissions. When an SCP denies DynamoDB actions, that deny overrides any IAM allow because AWS evaluates the SCP condition first as a service control filter. Therefore, the effective permission is Deny, not Allow, so this statement is incorrect.

  • ✓

    The user cannot perform PutItem because the SCP denies all DynamoDB actions and IAM allows are overridden.

    Why this is correct

    The SCP explicitly denies all DynamoDB actions for the OU, and service control policies are evaluated before IAM identity policies. Because a deny in an SCP always takes precedence over an allow in an IAM policy, the user's PutItem call will be denied even if the attached IAM policy grants it. This is the correct outcome under AWS's policy evaluation model.

  • ✗

    The user cannot perform PutItem because the SCP applies only to the root account.

    Why it's wrong here

    An SCP attached to an OU applies to every account in that OU, which includes all IAM users, roles, and root users within those accounts. It does not apply only to the root account of the organization; the only way it would be limited is if it were attached solely to a specific account. Since the scenario states the OU has an SCP, the user is subject to it, so this reason is false.

  • ✗

    The user can perform PutItem only if the SCP has an explicit allow.

    Why it's wrong here

    An explicit Allow in an SCP would not overcome a Deny because SCPs are not permission-granting; they are guardrails that filter what IAM policies can grant. Moreover, the deny of all DynamoDB actions is absolute, and a conflicting allow would be evaluated as a negative final decision. There is no scenario under AWS evaluation logic where an SCP allow can reverse an SCP deny.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.