SCS-C02 Management and Security Governance Practice Question
Which THREE AWS services can be used to centrally manage and audit permissions across multiple accounts in AWS Organizations?
⚠ Common exam trap
The trap is selecting security services by name association — candidates see 'Inspector' or 'Shield' and assume they relate to permissions, when only Access Analyzer, CloudTrail, and Config actually provide centralized permission auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM Access Analyzer
AWS IAM Access Analyzer (C) is correct because it continuously analyzes resource policies across accounts in AWS Organizations to identify resources shared with external entities, helping centrally manage and audit permissions. AWS CloudTrail (D) is correct because it records API activity across all accounts in an organization into a centralized trail, enabling auditing of who did what and when for permission-related changes. AWS Config (E) is correct because it continuously assesses and records resource configurations and policy compliance across accounts, allowing centralized auditing of permission-related configuration drift. Amazon Inspector (A) is not correct because it is a vulnerability management service for EC2, Lambda, and container images, not a permissions auditing tool. AWS Shield (B) is not correct because it is a managed DDoS protection service, unrelated to centrally managing or auditing permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Amazon Inspector
Why it's wrong here
Amazon Inspector is a vulnerability management service that continuously scans EC2 instances and container images for software vulnerabilities and unintended network exposure. It does not evaluate IAM policies, resource policies, or cross-account access patterns, so it cannot provide centralized visibility into who has access to what across accounts. Its findings relate to CVEs and network reachability, not permission management.
- ✗
AWS Shield
Why it's wrong here
AWS Shield is a managed distributed denial-of-service (DDoS) protection service that safeguards applications at the network and transport layers (with Shield Advanced adding application-layer mitigations). It operates on traffic flow and has no awareness of IAM principals, policies, or resource permissions. Therefore it is not a tool for centrally managing or monitoring permissions across an AWS organization.
- ✓
AWS IAM Access Analyzer
Why this is correct
AWS IAM Access Analyzer provides centralized visibility into resource-based policies across your account or entire AWS organization by continuously generating findings when a resource is shared with external principals. It examines policies attached to S3 buckets, IAM roles, KMS keys, and Secrets Manager secrets, flagging access from outside your organization's trusted boundary. This makes it a core service for monitoring and managing external permission exposure at scale.
- ✓
AWS CloudTrail
Why this is correct
AWS CloudTrail records API activity, including IAM and resource policy changes, and with an organization trail you can deliver logs from every account in AWS Organizations to a single S3 bucket and CloudWatch Logs. This provides a central audit trail for who made a call, when, from where, and with which permissions, enabling you to monitor permission-related events across all accounts. It supports central management and oversight by making actions auditable, not by configuring permissions itself.
- ✓
AWS Config
Why this is correct
AWS Config continuously records and evaluates the configuration of AWS resources, and with a multi-account aggregator you can collect configuration and compliance snapshots from every account in your organization into a single view. Using managed rules such as iam-user-unused-credentials-check or s3-bucket-public-write-prohibited, you can enforce and track permission-related compliance centrally. This makes Config a key service for centrally managing and monitoring the state of permissions and access that rely on resource configurations.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.