Courseiva

SCS-C02 Management and Security Governance Practice Question

A security team needs to centrally manage permissions for multiple AWS accounts. Which AWS service should they use?

⚠ Common exam trap

Test-takers frequently confuse AWS IAM (which manages permissions within a single account) with the need for cross-account permission management, leading them to select IAM instead of recognizing that AWS Organizations with SCPs is the correct service for central governance across multiple accounts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Organizations with service control policies (SCPs)

AWS Organizations with service control policies (SCPs) is the correct choice because SCPs allow you to centrally manage permissions across multiple AWS accounts by defining maximum permissions for member accounts. Unlike IAM policies that are attached to users or roles within a single account, SCPs act as a guardrail at the organization or organizational unit (OU) level, restricting what actions accounts and their IAM principals can perform, even if the account's own IAM policies allow more.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS IAM

    Why it's wrong here

    AWS IAM is fundamentally per-account: users, groups, roles, and policies are scoped within a single AWS account. An admin in one account cannot use IAM to set or restrict permissions for identities in other accounts; cross-account access requires manually configuring roles and trust policies in each account. This makes IAM unsuitable for centrally managing permissions across multiple accounts at once.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config is a compliance and auditing service that records resource configurations and evaluates them against rules to detect drift from desired settings. It can identify resources that violate policies (e.g., an overly permissive IAM role) but it cannot enforce, grant, or centrally manage permissions. Config reports on noncompliance after the fact and does not provide the control plane needed for central permission management.

  • ✓

    AWS Organizations with service control policies (SCPs)

    Why this is correct

    AWS Organizations gives you a central management structure for all your AWS accounts, and service control policies (SCPs) let you apply permission guardrails at the root, organizational unit (OU), or account level. SCPs restrict the maximum allowed actions for IAM principals in member accounts, but they do not grant permissions—they work alongside IAM policies to enforce central restrictions across the entire organization. This is the correct service because it provides centralized, cross-account permission governance that IAM alone cannot achieve.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail is exclusively a logging and monitoring service: it records API activity, who made the call, from which IP, and with what parameters, for audit and security analysis. It does not have any capability to set, modify, or enforce permissions; it is purely a detective control. While CloudTrail logs can reveal permission misuse, it cannot centrally manage or restrict permissions across accounts, so it is not a solution for this requirement.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.