SCS-C02 Management and Security Governance Practice Question
A company uses AWS Organizations with SCPs. The security team wants to ensure that no IAM user can be created without MFA. Which SCP should be applied at the root OU?
⚠ Common exam trap
Watch out — candidates often confuse SCPs with IAM policies, thinking an IAM policy can enforce MFA at the root OU level, but SCPs are the only mechanism that can apply organization-wide restrictions on actions like `iam:CreateUser`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deny iam:CreateUser unless the request includes a condition for MFA
It uses a Service Control Policy (SCP) to deny the `iam:CreateUser` action unless the request includes a condition that MFA is present. SCPs are account-level permission boundaries in AWS Organizations, and this approach ensures that no IAM user can be created without MFA across all accounts in the organization, as SCPs are evaluated before any IAM policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deny iam:CreateUser unconditionally
Why it's wrong here
An unconditional deny on iam:CreateUser would block all user creation, regardless of whether the caller has authenticated with MFA. It is too broad: it prohibits even fully MFA-authenticated administrators from creating accounts, while still failing to enforce any MFA requirement on the users being created. The intended outcome is a conditional denial that inspects the aws:MultiFactorAuthPresent key, not a blanket ban on the action.
- ✗
Use an IAM policy to require MFA for API calls
Why it's wrong here
Requiring MFA for API calls through an IAM policy controls the sessions of the identity making the call, but it does not apply to the iam:CreateUser action's outcome. A caller who has already satisfied that IAM policy condition could still create a user with no MFA enrollment, because the policy contains no logic that inspects the new user's attributes. An IAM policy is also not an SCP: it cannot be applied organization-wide to enforce the MFA requirement on the CreateUser operation at the account level.
- ✓
Deny iam:CreateUser unless the request includes a condition for MFA
Why this is correct
This SCP denies iam:CreateUser when the aws:MultiFactorAuthPresent condition key evaluates to false, effectively allowing the action only for callers who authenticated with MFA. Because SCPs apply to all principals in an AWS organization, this check is enforced regardless of the permissions granted by an individual IAM policy. The Deny statement with a Bool condition is the precise, organizational-level mechanism that prevents creation of users without an MFA requirement.
- ✗
Attach an IAM policy to all users requiring MFA
Why it's wrong here
Attaching an IAM policy to all users cannot be performed by an SCP; IAM policies are attached via IAM, not through AWS Organizations. Even if every existing user received a policy requiring MFA, a new user created later would not automatically receive that policy, leaving a gap. This approach also does nothing to prevent an administrator from creating a user without the MFA policy attached, whereas an SCP evaluates the CreateUser request itself.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.