Courseiva

SCS-C02 Management and Security Governance Practice Question

An organization uses AWS Organizations and wants to restrict the use of specific EC2 instance types across all member accounts. Which policy type should be used to enforce this restriction?

⚠ Common exam trap

The trap is assuming that IAM policies can be used organization-wide or that SCPs grant permissions; candidates must remember that SCPs are guardrails that limit permissions and are the only centralized policy type for multi-account restrictions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service control policy (SCP)

Service control policies (SCPs) are the only AWS Organizations policy type that can centrally restrict the maximum available permissions for all accounts in an organization or organizational unit. By attaching an SCP that denies the ec2:RunInstances action for specific instance types (using condition keys like ec2:InstanceType), the organization can enforce the restriction across all member accounts, regardless of their local IAM policies. SCPs do not grant permissions; they only filter them, so they are ideal for guardrails.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Resource-based policy

    Why it's wrong here

    Resource-based policies are attached to specific AWS resources, such as S3 buckets, KMS keys, or SQS queues, and they define which principals can access that particular resource. They are scoped to the resource itself, so they cannot restrict the availability or usage of a service across all accounts in an organization. Even if a resource-based policy denies a principal, that action only affects that resource and does not prevent the principal from using other services or resources elsewhere. Thus, it is not an effective mechanism for organization-wide service restriction.

  • ✗

    IAM policy

    Why it's wrong here

    An IAM policy is an identity-based policy attached to a user, group, or role within a single AWS account, and it defines what actions that identity can perform on specific resources. Since IAM policies are scoped to individual identities and accounts, they cannot be centrally applied to all accounts from an organization's management account, nor are they inherited by child accounts automatically. Moreover, IAM policies only affect principals when they are explicitly attached; an OU-level restriction across many accounts requires a governance mechanism like an SCP. Therefore, an IAM policy is not the correct tool for restricting services across an entire organization.

  • ✓

    Service control policy (SCP)

    Why this is correct

    A service control policy (SCP) is a feature of AWS Organizations that you attach to the organization root, an organizational unit (OU), or an individual account to centrally set the maximum permissions available to all principals within those accounts. SCPs do not grant permissions; instead, they act as a permission boundary, and their effects are inherited by all child accounts, making them the only option among these that can consistently restrict services across many accounts at once. For example, you can use an SCP to deny the use of a specific AWS service or the ability to leave the organization, which cannot be accomplished with IAM or resource-based policies alone. This makes the SCP the correct choice for organization-wide service restriction.

  • ✗

    AWS CloudFormation policy

    Why it's wrong here

    AWS CloudFormation is an infrastructure-as-code service for provisioning and updating AWS resources from templates; it is not a policy language for access control. CloudFormation stack policies are optional documents that protect resources during stack updates, but they do not govern which services an account can use or enforce restrictions across an organization. They are applied per stack at update time, not per account or OU, so they have no effect on whether users can call service APIs in other contexts. Consequently, a CloudFormation policy is not a valid mechanism for restricting services across accounts.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.