SCS-C02 Management and Security Governance Practice Question
A security engineer is designing a governance framework for a multi-account AWS environment. The engineer needs to ensure that all accounts comply with the principle of least privilege for IAM roles and that any non-compliant resources are automatically reported. Which two AWS services should the engineer use together to achieve this? (Choose TWO.)
⚠ Common exam trap
Many exam-takers confuse AWS Config (resource compliance evaluation) with AWS CloudTrail (API activity logging) or Amazon GuardDuty (threat detection), failing to recognize that only AWS Config can directly assess IAM role configurations against least privilege rules and automatically report non-compliance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Security Hub
AWS Security Hub is correct because it provides a comprehensive view of security alerts and compliance status across multiple AWS accounts, aggregating findings from various AWS services and third-party tools. AWS Config is correct because it continuously monitors and records AWS resource configurations, enabling you to define rules (e.g., IAM least privilege policies) and automatically evaluate resource compliance, triggering notifications or remediation actions for non-compliant resources. Together, Security Hub can ingest AWS Config rule compliance results as findings, allowing centralized reporting and automated response to IAM role violations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Security Hub
Why this is correct
AWS Security Hub is the correct choice because it provides a centralized view of security and compliance posture across AWS accounts. It ingests and aggregates findings from AWS Config, including IAM role compliance checks, and continuously runs controls from frameworks like CIS AWS Foundations Benchmark and AWS Foundational Security Best Practices. This allows a security engineer to create a governance framework that monitors IAM roles against least-privilege policies, with automated compliance reporting and a unified dashboard. Security Hub also integrates with AWS Organizations to aggregate findings from multiple accounts, making it the appropriate service for enterprise-wide IAM governance.
- ✗
AWS Service Catalog
Why it's wrong here
AWS Service Catalog is incorrect because it is designed to help organizations create, manage, and provision approved IT services and products, such as pre-configured EC2 instances or CloudFormation templates. It does not evaluate existing IAM roles or monitor their permissions against a least-privilege baseline. Service Catalog governs the deployment of new resources by enforcing tagging and IAM policies during provisioning, but it lacks the continuous compliance assessment and finding aggregation capabilities needed for an ongoing IAM governance framework. Therefore, it cannot provide the monitoring or reporting required for this use case.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty is incorrect because it is a threat detection service that continuously analyzes AWS logs, such as DNS queries, VPC Flow Logs, and CloudTrail management events, to identify malicious activity and unauthorized behavior. It does not assess IAM role configurations or evaluate whether permissions align with least-privilege principles. GuardDuty focuses on detecting anomalies and known threats, not on enforcing compliance standards or auditing role policies. While GuardDuty findings may indicate compromised credentials, it cannot be used to proactively govern and monitor IAM role permissions across an environment.
- ✓
AWS Config
Why this is correct
AWS Config is correct because it provides a comprehensive resource configuration recording and evaluation service that can assess IAM roles against compliance rules. Using managed rules like iam-policy-no-statements-with-admin-access or custom Lambda-based rules, AWS Config can continuously evaluate whether IAM roles adhere to least-privilege permissions. It records configuration changes to IAM roles and produces compliance status for each rule, which can be aggregated by AWS Security Hub. This makes AWS Config a key underlying component for implementing an IAM governance framework, though Security Hub provides the higher-level aggregation and reporting layer.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail is incorrect because it is primarily an API activity logging service that records actions taken by users, roles, or AWS services across an account. It does not evaluate IAM role configurations or compare role permissions against a least-privilege policy baseline. CloudTrail is useful for auditing who did what, when, and from where, which can support incident investigation and operational forensics. However, it lacks the configuration assessment and compliance rule engine needed to monitor IAM roles for governance purposes, making it unsuitable for this task.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.