SCS-C02 Management and Security Governance Practice Question
An organization uses AWS Organizations and wants to restrict the use of specific EC2 instance types across all member accounts. Which policy type should be used to enforce this restriction?
⚠ Common exam trap
The trap is assuming that IAM policies can be used organization-wide or that SCPs grant permissions; candidates must remember that SCPs are guardrails that limit permissions and are the only centralized policy type for multi-account restrictions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service control policy (SCP)
Service control policies (SCPs) are the only AWS Organizations policy type that can centrally restrict the maximum available permissions for all accounts in an organization or organizational unit. By attaching an SCP that denies the ec2:RunInstances action for specific instance types (using condition keys like ec2:InstanceType), the organization can enforce the restriction across all member accounts, regardless of their local IAM policies. SCPs do not grant permissions; they only filter them, so they are ideal for guardrails.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Resource-based policy
Why it's wrong here
Resource-based policies are attached to specific AWS resources, such as S3 buckets, KMS keys, or SQS queues, and they define which principals can access that particular resource. They are scoped to the resource itself, so they cannot restrict the availability or usage of a service across all accounts in an organization. Even if a resource-based policy denies a principal, that action only affects that resource and does not prevent the principal from using other services or resources elsewhere. Thus, it is not an effective mechanism for organization-wide service restriction.
- ✗
IAM policy
Why it's wrong here
An IAM policy is an identity-based policy attached to a user, group, or role within a single AWS account, and it defines what actions that identity can perform on specific resources. Since IAM policies are scoped to individual identities and accounts, they cannot be centrally applied to all accounts from an organization's management account, nor are they inherited by child accounts automatically. Moreover, IAM policies only affect principals when they are explicitly attached; an OU-level restriction across many accounts requires a governance mechanism like an SCP. Therefore, an IAM policy is not the correct tool for restricting services across an entire organization.
- ✓
Service control policy (SCP)
Why this is correct
A service control policy (SCP) is a feature of AWS Organizations that you attach to the organization root, an organizational unit (OU), or an individual account to centrally set the maximum permissions available to all principals within those accounts. SCPs do not grant permissions; instead, they act as a permission boundary, and their effects are inherited by all child accounts, making them the only option among these that can consistently restrict services across many accounts at once. For example, you can use an SCP to deny the use of a specific AWS service or the ability to leave the organization, which cannot be accomplished with IAM or resource-based policies alone. This makes the SCP the correct choice for organization-wide service restriction.
- ✗
AWS CloudFormation policy
Why it's wrong here
AWS CloudFormation is an infrastructure-as-code service for provisioning and updating AWS resources from templates; it is not a policy language for access control. CloudFormation stack policies are optional documents that protect resources during stack updates, but they do not govern which services an account can use or enforce restrictions across an organization. They are applied per stack at update time, not per account or OU, so they have no effect on whether users can call service APIs in other contexts. Consequently, a CloudFormation policy is not a valid mechanism for restricting services across accounts.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.