Courseiva

SCS-C02 Management and Security Governance Practice Question

What is the purpose of an AWS Service Control Policy (SCP) in AWS Organizations?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To set permission guardrails that restrict what actions accounts in the organization can perform.

SCPs are used to centrally control the maximum available permissions for all accounts in an organization. Option A is wrong because SCPs do not grant permissions; they restrict them. Option B is wrong because SCPs apply to all users and roles, not just root. Option C is wrong because SCPs are not for monitoring; they are permission guardrails.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To grant specific permissions to users in member accounts.

    Why it's wrong here

    SCPs are boundary policies, not grant mechanisms. They can only deny or explicitly allow actions within the maximum permission envelope for an account, but they never by themselves grant a user or role any actual permissions. A principal still needs an IAM identity-based or resource-based policy to receive access; without that, an SCP cannot create it. Therefore, to grant specific permissions to users, you must attach IAM policies, not SCPs.

  • ✗

    To restrict only the root user of each member account.

    Why it's wrong here

    Service Control Policies apply to all IAM users and roles within a member account, not solely the root user; they cannot target the root user in isolation because SCPs operate on the account level, affecting every principal except the management account root. This option is tempting because SCPs are often used to enforce broad security guardrails, and restricting the root user is a common compliance goal; however, that specific restriction would require a different mechanism, such as an IAM policy attached directly to the root user or an account-level block via the AWS Organizations console, not an SCP.

  • ✗

    To monitor and log API activity across the organization.

    Why it's wrong here

    SCPs define the maximum permissions available to accounts in an organisation; they neither record nor monitor API calls. It is tempting because both features sit within AWS Organizations governance, and it would be correct if the requirement were to capture an audit trail of API activity, which CloudTrail provides.

  • ✓

    To set permission guardrails that restrict what actions accounts in the organization can perform.

    Why this is correct

    SCPs set permission guardrails by defining the maximum actions that principals in an account or organizational unit can perform. When attached at the organization, OU, or account level, an SCP constrains all IAM users and roles in that account—including the account root user—by filtering what identity-based and resource-based policies are allowed to grant. They act as a boundary that limits, but never grants, permissions, making them the correct mechanism for organization-wide controls such as denying the deletion of CloudTrail logs or restricting access to certain AWS services.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.