Courseiva

SCS-C02 Management and Security Governance Practice Question

A company uses AWS Organizations with SCPs. The security team wants to ensure that no IAM user can be created without MFA. Which SCP should be applied at the root OU?

⚠ Common exam trap

Watch out — candidates often confuse SCPs with IAM policies, thinking an IAM policy can enforce MFA at the root OU level, but SCPs are the only mechanism that can apply organization-wide restrictions on actions like `iam:CreateUser`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deny iam:CreateUser unless the request includes a condition for MFA

It uses a Service Control Policy (SCP) to deny the `iam:CreateUser` action unless the request includes a condition that MFA is present. SCPs are account-level permission boundaries in AWS Organizations, and this approach ensures that no IAM user can be created without MFA across all accounts in the organization, as SCPs are evaluated before any IAM policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deny iam:CreateUser unconditionally

    Why it's wrong here

    An unconditional deny on iam:CreateUser would block all user creation, regardless of whether the caller has authenticated with MFA. It is too broad: it prohibits even fully MFA-authenticated administrators from creating accounts, while still failing to enforce any MFA requirement on the users being created. The intended outcome is a conditional denial that inspects the aws:MultiFactorAuthPresent key, not a blanket ban on the action.

  • ✗

    Use an IAM policy to require MFA for API calls

    Why it's wrong here

    Requiring MFA for API calls through an IAM policy controls the sessions of the identity making the call, but it does not apply to the iam:CreateUser action's outcome. A caller who has already satisfied that IAM policy condition could still create a user with no MFA enrollment, because the policy contains no logic that inspects the new user's attributes. An IAM policy is also not an SCP: it cannot be applied organization-wide to enforce the MFA requirement on the CreateUser operation at the account level.

  • ✓

    Deny iam:CreateUser unless the request includes a condition for MFA

    Why this is correct

    This SCP denies iam:CreateUser when the aws:MultiFactorAuthPresent condition key evaluates to false, effectively allowing the action only for callers who authenticated with MFA. Because SCPs apply to all principals in an AWS organization, this check is enforced regardless of the permissions granted by an individual IAM policy. The Deny statement with a Bool condition is the precise, organizational-level mechanism that prevents creation of users without an MFA requirement.

  • ✗

    Attach an IAM policy to all users requiring MFA

    Why it's wrong here

    Attaching an IAM policy to all users cannot be performed by an SCP; IAM policies are attached via IAM, not through AWS Organizations. Even if every existing user received a policy requiring MFA, a new user created later would not automatically receive that policy, leaving a gap. This approach also does nothing to prevent an administrator from creating a user without the MFA policy attached, whereas an SCP evaluates the CreateUser request itself.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.