SCS-C02 Management and Security Governance Practice Question
Which TWO AWS services can be used to centrally manage and audit permissions across multiple AWS accounts? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Organizations
AWS Organizations provides a central view of all accounts and can apply SCPs. IAM Access Analyzer analyzes resource policies across accounts to identify public or cross-account access. AWS Config evaluates resource configurations but does not centrally manage permissions. AWS CloudTrail logs API calls but does not manage permissions. AWS SSO manages user access but not resource permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Config
Why it's wrong here
AWS Config continuously records resource configuration changes and evaluates them against custom or managed rules, but it has no authority to grant, deny, or modify IAM policies. It can only flag noncompliant resources and produce a configuration history, making it a visibility and compliance tool rather than a central permissions management plane. Therefore, while Config helps audit whether policies are followed, it cannot centrally govern or enforce access controls across accounts.
- ✗
AWS CloudTrail
Why it's wrong here
AWS CloudTrail captures a detailed audit log of every API call made in an account, along with the identity, source IP, and time, but the service does not alter or administer any permission model. It is a read-only telemetry service for post-event investigation and operational forensics, not a policy control point. Thus, CloudTrail provides evidence of who did what, but it cannot centrally manage or restrict permissions.
- ✓
AWS Organizations
Why this is correct
AWS Organizations is the correct service for centrally managing multiple accounts and applying service control policies (SCPs) that place guardrails on the maximum permissions available to IAM principals within member accounts. SCPs act as a policy filter, allowing you to forbid or allow specific AWS services and actions at the organizational, organizational unit, or account level without modifying the IAM policies themselves. This makes Organizations a central control plane for permission boundaries across an entire AWS environment.
- ✗
AWS Single Sign-On
Why it's wrong here
AWS Single Sign-On, now called IAM Identity Center, centrally manages workforce identities and their assigned access to AWS accounts and business applications through SSO and permission sets, but it does not govern what those users can do to resources. The permission sets it creates map to IAM roles, but the actual fine-grained resource actions are still defined by IAM policies attached to those roles. It is an identity and assignment hub, not a service for centrally managing resource-level permissions across accounts.
- ✓
IAM Access Analyzer
Why this is correct
IAM Access Analyzer provides centralized visibility into resource-based policies across accounts by using external access analyzers to identify resources shared with external principals, including public access and cross-account access. It also includes policy generation and validation tools that help you craft least-privilege permissions based on actual usage. This enables security teams to proactively manage and reduce unintended access at scale, making it a key service for central access governance.
Go deeper
Related to this question
About these practice questions
This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.