SCS-C02 Management and Security Governance Practice Question
A company wants to centrally manage and enforce security policies across multiple AWS accounts using AWS Organizations. Which THREE actions should be taken? (Choose three.)
⚠ Common exam trap
SCS-C02 often tests the misconception that root users are needed for cross-account administration — candidates forget that IAM roles with trust policies are the secure, auditable alternative.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable all features in AWS Organizations and create service control policies (SCPs) to restrict actions.
Option B is correct because enabling all features in AWS Organizations unlocks advanced governance capabilities, including service control policies (SCPs), which are the mechanism for centrally restricting the maximum available permissions across member accounts. Option C is correct because AWS CloudTrail provides centralized audit logging of API activity; creating a trail that applies to all accounts and delivers logs to a single S3 bucket in a central account gives the company visibility and evidence of policy enforcement across the organization. Option D is correct because IAM roles in member accounts with trust policies allowing the management account to assume them enable secure cross-account administration without sharing long-term credentials, which is the recommended pattern for centralized management. Option A is not appropriate because the root user of each member account should not be used for routine administrative tasks; it has unrestricted permissions, cannot be constrained by SCPs, and should be protected with MFA and reserved for break-glass scenarios. Option E is incorrect because disabling CloudTrail in member accounts would eliminate the audit trail needed to verify and enforce security policies, undermining the centralized governance goal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the root user of each member account for administrative tasks.
Why it's wrong here
The root user in each member account has unconstrained, irreversible permissions that IAM policies cannot limit, and its use bypasses IAM-level auditing and least privilege. Everyday administration should instead rely on IAM roles with scoped permissions, while root user access, if retained, should be guarded with MFA and used only for account-recovery tasks that only the root user can perform.
- ✓
Enable all features in AWS Organizations and create service control policies (SCPs) to restrict actions.
Why this is correct
Enabling all features in AWS Organizations and creating service control policies (SCPs) is the foundational step for central governance because SCPs apply boundary limits across every principal in member accounts, including the root user, without needing to log in to each account. SCPs can deny high-risk actions such as disabling CloudTrail, deleting IAM roles, or leaving the organization, and they work alongside IAM policies to enforce a global guardrail.
- ✓
Use AWS CloudTrail to log API calls in all accounts and deliver logs to a centralized S3 bucket.
Why this is correct
Centralizing CloudTrail logs from all member accounts into a single S3 bucket with a bucket policy that only permits the CloudTrail service to write creates an immutable audit trail of every API call, including actions performed by the root user, IAM roles, and federated identities. This centralized visibility is essential for detecting misconfigurations, investigating security incidents, and satisfying compliance requirements, and is a best practice in multi-account architectures.
- ✓
Create IAM roles in member accounts that grant cross-account access from the management account.
Why this is correct
Creating IAM roles in each member account that can be assumed from the management account (or via federation) enables secure, auditable, and centralized administration without distributing long-lived credentials. These cross-account roles can be scoped with permissions policies to allow only specific administrative actions, and every assumption generates a CloudTrail event of who accessed which account, so actions can be traced back to an individual or automated workflow.
- ✗
Disable CloudTrail in member accounts to reduce costs.
Why it's wrong here
Disabling CloudTrail in member accounts may reduce costs but eliminates the ability to audit API activity, leaving the organization blind to unauthorized actions, data exfiltration, or configuration changes. Security monitoring and compliance frameworks require comprehensive logging, and organizations should use SCPs to prevent member accounts from disabling CloudTrail or deleting the centralized log delivery, not reduce it to save money.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.