Enforce Least Privilege with IAM Policies & SCPs
Which TWO actions are valid ways to enforce the principle of least privilege in an AWS environment?
Quick Answer
Enforcing least privilege in AWS is about applying restriction at two different layers that reinforce each other rather than relying on a single control. IAM policies attached to individual users or roles should be scoped to grant only the specific actions those principals actually need, the fine-grained, per-principal layer of least privilege. Service control policies operate at a different layer: attached to an organizational unit or account within AWS Organizations, they set an outer boundary on what any principal in that account can ever do, regardless of how permissive their individual IAM policies might be, making them effective for enforcing guardrails consistently across every account and user at once. The options that fail here all share the same problem: they grant broad or unrestricted access rather than narrowing it, whether that is using the root user for routine administrative tasks, writing a bucket policy that opens access to every IAM user instead of specific ones, or attaching a fully permissive managed policy like AdministratorAccess to a principal that doesn't need it. When a question asks which actions enforce least privilege, look for mechanisms that narrow or restrict what is allowed, applied at either the individual policy level or the organizational boundary level, and treat any option that broadens or grants blanket access as automatically disqualified no matter how convenient it sounds.
⚠ Common exam trap
SCS-C02 often tests the difference between IAM policies and SCPs. Candidates may think SCPs alone are sufficient, but they must be combined with IAM policies that grant only necessary actions. Also, candidates may confuse least privilege with other concepts like defense in depth.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant only the necessary actions in IAM policies
Option C is correct because least privilege means granting identities only the specific IAM actions and resources they actually need, so scoping IAM policy statements to the minimum required actions directly enforces that principle. Option D is correct because AWS Organizations Service Control Policies (SCPs) set a permissions boundary that can explicitly deny actions not required across accounts or OUs, preventing even otherwise-allowed IAM permissions from being used. Option A is wrong because using the root user for daily administration violates least privilege, as root has unrestricted access and should be reserved for a few account-level tasks. Option B is wrong because an S3 bucket policy allowing all IAM users grants broad access rather than the minimum necessary. Option E is wrong because attaching AdministratorAccess to all users gives full administrative permissions, the opposite of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the root user for daily administration
Why it's wrong here
The root user holds unrestricted account-wide permissions that cannot be scoped, so daily use violates least privilege. Root is intended only for tasks requiring it, such as closing the account or changing the support plan.
- ✗
Use S3 bucket policies to allow all IAM users
Why it's wrong here
Allowing all IAM users in an S3 bucket policy grants broad access, contradicting least privilege, which requires granting only the specific actions and resources each principal needs. Bucket policies are correct for scoping cross-account or public access to defined principals.
- ✓
Grant only the necessary actions in IAM policies
Why this is correct
IAM policies define which actions an identity may perform on which resources; listing only the required actions means any unlisted API call is implicitly denied. This directly enforces least privilege at the identity-policy layer, satisfying the stem's requirement to grant no more than the task needs.
- ✓
Use SCPs to deny actions that are not required
Why this is correct
Service control policies set the maximum available permissions for accounts and OUs, and an explicit Deny overrides any identity-based Allow. Denying unrequired actions therefore caps what any principal can do, enforcing least privilege at the organisation level rather than per identity.
- ✗
Assign the AdministratorAccess managed policy to all users
Why it's wrong here
AdministratorAccess grants full permissions to every user, directly violating least privilege, which demands narrowly scoped policies. Managed policies are appropriate when a defined job function genuinely needs that exact permission set, not blanket admin rights.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SCS-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions can be taken to enforce the principle of least privilege for IAM users in an AWS account? (Choose two.)
medium- ✓ A.Use IAM roles with temporary credentials for access
- B.Grant full administrative access to all users to simplify management
- C.Use service control policies (SCPs) to restrict user permissions
- D.Use the root user for daily administrative tasks
- ✓ E.Regularly review and remove unused IAM policies
Why A: Option A is correct because assigning IAM roles that issue temporary credentials via AWS STS (e.g., AssumeRole) eliminates long-lived access keys and lets you scope permissions tightly to only what each task requires, directly enforcing least privilege. Option E is correct because regularly auditing IAM policies and removing unused or overly broad permissions (for example, via IAM Access Analyzer or credential reports) shrinks the effective permission set over time, which is a core least-privilege practice. Option B is wrong because granting full administrative access to all users violates least privilege by massively over-provisioning permissions. Option C is wrong in this context because SCPs apply to AWS Organizations accounts/OUs as permission guardrails, not to individual IAM users within an account, so they cannot directly restrict a specific user's permissions. Option D is wrong because using the root user for daily administrative tasks is an anti-pattern that grants unrestricted, non-scoped access and should be avoided in favor of scoped IAM identities.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.