Courseiva

SCS-C02 Management and Security Governance Practice Question

Which THREE AWS services can be used to centrally manage and audit permissions across multiple accounts in AWS Organizations?

⚠ Common exam trap

The trap is selecting security services by name association — candidates see 'Inspector' or 'Shield' and assume they relate to permissions, when only Access Analyzer, CloudTrail, and Config actually provide centralized permission auditing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS IAM Access Analyzer

AWS IAM Access Analyzer (C) is correct because it continuously analyzes resource policies across accounts in AWS Organizations to identify resources shared with external entities, helping centrally manage and audit permissions. AWS CloudTrail (D) is correct because it records API activity across all accounts in an organization into a centralized trail, enabling auditing of who did what and when for permission-related changes. AWS Config (E) is correct because it continuously assesses and records resource configurations and policy compliance across accounts, allowing centralized auditing of permission-related configuration drift. Amazon Inspector (A) is not correct because it is a vulnerability management service for EC2, Lambda, and container images, not a permissions auditing tool. AWS Shield (B) is not correct because it is a managed DDoS protection service, unrelated to centrally managing or auditing permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Amazon Inspector

    Why it's wrong here

    Amazon Inspector is a vulnerability management service that continuously scans EC2 instances and container images for software vulnerabilities and unintended network exposure. It does not evaluate IAM policies, resource policies, or cross-account access patterns, so it cannot provide centralized visibility into who has access to what across accounts. Its findings relate to CVEs and network reachability, not permission management.

  • ✗

    AWS Shield

    Why it's wrong here

    AWS Shield is a managed distributed denial-of-service (DDoS) protection service that safeguards applications at the network and transport layers (with Shield Advanced adding application-layer mitigations). It operates on traffic flow and has no awareness of IAM principals, policies, or resource permissions. Therefore it is not a tool for centrally managing or monitoring permissions across an AWS organization.

  • ✓

    AWS IAM Access Analyzer

    Why this is correct

    AWS IAM Access Analyzer provides centralized visibility into resource-based policies across your account or entire AWS organization by continuously generating findings when a resource is shared with external principals. It examines policies attached to S3 buckets, IAM roles, KMS keys, and Secrets Manager secrets, flagging access from outside your organization's trusted boundary. This makes it a core service for monitoring and managing external permission exposure at scale.

  • ✓

    AWS CloudTrail

    Why this is correct

    AWS CloudTrail records API activity, including IAM and resource policy changes, and with an organization trail you can deliver logs from every account in AWS Organizations to a single S3 bucket and CloudWatch Logs. This provides a central audit trail for who made a call, when, from where, and with which permissions, enabling you to monitor permission-related events across all accounts. It supports central management and oversight by making actions auditable, not by configuring permissions itself.

  • ✓

    AWS Config

    Why this is correct

    AWS Config continuously records and evaluates the configuration of AWS resources, and with a multi-account aggregator you can collect configuration and compliance snapshots from every account in your organization into a single view. Using managed rules such as iam-user-unused-credentials-check or s3-bucket-public-write-prohibited, you can enforce and track permission-related compliance centrally. This makes Config a key service for centrally managing and monitoring the state of permissions and access that rely on resource configurations.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.