SCS-C02 Identity and Access Management Practice Question
A security engineer is reviewing an AWS account and notices that multiple IAM users have full administrative access. The company policy requires that users have only the permissions necessary to perform their job. What is the MOST secure and efficient way to enforce this policy?
⚠ Common exam trap
SCS-C02 often tests the misconception that SCPs grant permissions or that per-user inline policies are equivalent to group-based managed policies — candidates must recognize that SCPs are guardrails and that groups are the efficient least-privilege mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use an IAM group for each job function, attach appropriate managed policies to the group, and add users to the group.
Using IAM groups mapped to job functions and attaching managed policies to those groups is the most secure and efficient approach. It enforces least privilege by granting only the permissions each role needs, and it centralizes administration so permissions are managed in one place rather than per user. This aligns with AWS best practices for identity management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an IAM policy that denies all actions except those specifically allowed, and attach it to each user.
Why it's wrong here
Attaching a per-user deny-all-except-allow policy creates a rigid, standalone permission set for each identity, so every change requires editing the same JSON in each user's policy. Because AWS introduced new services and actions after a policy is deployed, an explicit NotAction deny can accidentally block legitimate actions that weren't listed, and this approach lacks the central management that IAM groups provide. This method does not scale past a small number of users and diverges from AWS's recommended job-function-based access control.
- ✓
Use an IAM group for each job function, attach appropriate managed policies to the group, and add users to the group.
Why this is correct
IAM groups are the recommended way to organize permissions by job function: you attach a managed policy (AWS-managed or customer-managed) to the group, and any user added to the group automatically receives those permissions. This separates identity management from permission management, so updating a group policy affects all members consistently, and you can onboard/offboard users simply by adding or removing them from the group. Groups also help you adhere to least privilege without duplicating policy content across individual users.
- ✗
Use an SCP in AWS Organizations to deny all actions by default.
Why it's wrong here
SCPs in AWS Organizations are guardrails that define the maximum permissions for all principals in a member account; they cannot be used to selectively grant or deny actions for specific IAM users or groups within that account. The engineer in a single-account review typically does not have the authority or even the correct location to create SCPs, as they are managed at the organization root. A default-deny SCP would lock down the entire account, including IAM users and roles, and provide no mechanism for differentiating job functions, making it the wrong tool for granular permission management.
- ✗
Assign an inline policy to each user that specifies allowed actions.
Why it's wrong here
An inline policy embedded directly in a single IAM user may handle a one-off case, but it cannot be reused across users, so maintaining the same permissions for multiple users requires duplicating the policy JSON in every account. This also makes audits difficult because policies are scattered and hard to locate, and unlike managed policies, inline policies do not support versioning or easy rollback. In a large user population, this approach is highly expensive to manage and error-prone, so it is not the correct solution.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.