Deny Console Access with SCP
A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM user in any account can create access keys. Which policy type should be used to enforce this restriction across all accounts?
⚠ Common exam trap
SCS-C02 often tests the distinction between SCPs (organization-wide guardrails) and permissions boundaries (per-entity limits), so candidates who pick permissions boundaries miss the cross-account enforcement requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Service Control Policy (SCP)
Service Control Policies (SCPs) in AWS Organizations define the maximum permissions for all IAM principals in member accounts. An SCP that denies the iam:CreateAccessKey action applied at the organization or OU level prevents any IAM user in any account from creating access keys, regardless of their identity-based policies. This is the correct mechanism for enforcing restrictions across all accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IAM identity-based policy
Why it's wrong here
An IAM identity-based policy grants permissions to a specific IAM user, group, or role and must be individually attached in each account. It does not apply to the account root user, and it has no effect on principals in other AWS accounts until you deploy it to every identity in every account. This makes it an impractical and incomplete mechanism for centrally denying an action across an organization, unlike an SCP which applies automatically to all principals in the target account.
- ✗
Resource-based policy
Why it's wrong here
Resource-based policies are attached to a resource, such as an S3 bucket, an SQS queue, or a KMS key, and they define which principals may access that particular resource. They can include an explicit Deny, but that Deny only governs requests made to the specific resource; it does not constrain the calling principal's actions on any other service or resource. Therefore, a resource-based policy cannot establish an account-level or organization-wide denial.
- ✗
Permissions boundary
Why it's wrong here
A permissions boundary is an IAM-managed policy that sets the maximum permissions available to an individual IAM user or role, but it is not an organizational control. It must be attached to each principal separately, does not affect the account root user, and does not restrict principals that do not carry the boundary. Thus, a permissions boundary cannot enforce a uniform denial across all accounts and all principals, even though it can limit a single principal's effective permissions.
- ✓
Service Control Policy (SCP)
Why this is correct
Service Control Policies (SCPs) are organization policies attached to the AWS Organizations root, an organizational unit, or an individual account, and they apply to every IAM principal—including the root user—within the affected accounts. An explicit Deny in an SCP overrides any Allow generated by identity-based, resource-based, or permissions-boundary policies, but an SCP itself never grants permissions. This makes SCP the correct choice for an account-wide, centrally managed restriction that cannot be bypassed by individual principals.
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.