SCS-C02 Management and Security Governance Practice Question
A security engineer needs to centrally manage and enforce security policies across multiple AWS accounts in an organization. Which AWS service should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Organizations with SCPs
AWS Organizations with Service Control Policies (SCPs) allows central policy management across accounts. Firewall Manager focuses on VPC security, not general policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS CloudFormation StackSets
Why it's wrong here
AWS CloudFormation StackSets is an infrastructure-as-code deployment service that provisions identical CloudFormation stacks across multiple accounts and Regions from a single admin account. It is not a policy evaluation or enforcement service: it cannot centrally evaluate API calls, define permission boundaries, or impose guardrails on IAM principals. While you could use StackSets to deploy individual guardrail resources such as AWS Config rules, that is a manual template lifecycle, not native central policy management, and it provides no intrinsic enforcement of those policies.
- ✗
AWS IAM
Why it's wrong here
AWS IAM operates entirely within the boundary of a single AWS account. IAM users, roles, and policies are account-scoped entities, and there is no IAM endpoint in one account that can centrally manage or enforce permissions for principals in other accounts. IAM policies define what an identity can do inside that account, but they do not propagate across accounts in an organization. Centralized cross-account permission enforcement requires an organization-level mechanism, not IAM alone.
- ✗
AWS Firewall Manager
Why it's wrong here
AWS Firewall Manager is a security policy management service that centrally configures and enforces network security rules — specifically VPC security groups, AWS WAF web ACLs, AWS Shield Advanced protections, and Network Firewall policies — across accounts in an AWS Organization. It does not manage general security policies such as IAM permissions, resource-level access controls, or API action restrictions. Firewall Manager's scope is limited to firewall-related protections, so it cannot enforce the kind of broad permission guardrails that an SCP can.
- ✓
AWS Organizations with SCPs
Why this is correct
AWS Organizations with Service Control Policies (SCPs) is the correct choice because SCPs are centralized policy documents that attach to the organization root, organizational units, or individual accounts and define the maximum allowed permissions for all IAM principals in those accounts. SCPs act as guardrails that restrict what services and actions can be performed, and they are enforced by a central governance layer independent of the account's local IAM administrators. Because SCPs are managed from the management account of the organization, they provide a single point to centrally administer and enforce security policies across every member account.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.