Courseiva

Deny Console Access with SCP

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM user in any account can create access keys. Which policy type should be used to enforce this restriction across all accounts?

⚠ Common exam trap

SCS-C02 often tests the distinction between SCPs (organization-wide guardrails) and permissions boundaries (per-entity limits), so candidates who pick permissions boundaries miss the cross-account enforcement requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Service Control Policy (SCP)

Service Control Policies (SCPs) in AWS Organizations define the maximum permissions for all IAM principals in member accounts. An SCP that denies the iam:CreateAccessKey action applied at the organization or OU level prevents any IAM user in any account from creating access keys, regardless of their identity-based policies. This is the correct mechanism for enforcing restrictions across all accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IAM identity-based policy

    Why it's wrong here

    An IAM identity-based policy grants permissions to a specific IAM user, group, or role and must be individually attached in each account. It does not apply to the account root user, and it has no effect on principals in other AWS accounts until you deploy it to every identity in every account. This makes it an impractical and incomplete mechanism for centrally denying an action across an organization, unlike an SCP which applies automatically to all principals in the target account.

  • ✗

    Resource-based policy

    Why it's wrong here

    Resource-based policies are attached to a resource, such as an S3 bucket, an SQS queue, or a KMS key, and they define which principals may access that particular resource. They can include an explicit Deny, but that Deny only governs requests made to the specific resource; it does not constrain the calling principal's actions on any other service or resource. Therefore, a resource-based policy cannot establish an account-level or organization-wide denial.

  • ✗

    Permissions boundary

    Why it's wrong here

    A permissions boundary is an IAM-managed policy that sets the maximum permissions available to an individual IAM user or role, but it is not an organizational control. It must be attached to each principal separately, does not affect the account root user, and does not restrict principals that do not carry the boundary. Thus, a permissions boundary cannot enforce a uniform denial across all accounts and all principals, even though it can limit a single principal's effective permissions.

  • ✓

    Service Control Policy (SCP)

    Why this is correct

    Service Control Policies (SCPs) are organization policies attached to the AWS Organizations root, an organizational unit, or an individual account, and they apply to every IAM principal—including the root user—within the affected accounts. An explicit Deny in an SCP overrides any Allow generated by identity-based, resource-based, or permissions-boundary policies, but an SCP itself never grants permissions. This makes SCP the correct choice for an account-wide, centrally managed restriction that cannot be bypassed by individual principals.

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.