Courseiva

SCS-C02 Management and Security Governance Practice Question

Which TWO AWS services can be used to centrally manage and audit permissions across multiple AWS accounts? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Organizations

AWS Organizations provides a central view of all accounts and can apply SCPs. IAM Access Analyzer analyzes resource policies across accounts to identify public or cross-account access. AWS Config evaluates resource configurations but does not centrally manage permissions. AWS CloudTrail logs API calls but does not manage permissions. AWS SSO manages user access but not resource permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config continuously records resource configuration changes and evaluates them against custom or managed rules, but it has no authority to grant, deny, or modify IAM policies. It can only flag noncompliant resources and produce a configuration history, making it a visibility and compliance tool rather than a central permissions management plane. Therefore, while Config helps audit whether policies are followed, it cannot centrally govern or enforce access controls across accounts.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    AWS CloudTrail captures a detailed audit log of every API call made in an account, along with the identity, source IP, and time, but the service does not alter or administer any permission model. It is a read-only telemetry service for post-event investigation and operational forensics, not a policy control point. Thus, CloudTrail provides evidence of who did what, but it cannot centrally manage or restrict permissions.

  • ✓

    AWS Organizations

    Why this is correct

    AWS Organizations is the correct service for centrally managing multiple accounts and applying service control policies (SCPs) that place guardrails on the maximum permissions available to IAM principals within member accounts. SCPs act as a policy filter, allowing you to forbid or allow specific AWS services and actions at the organizational, organizational unit, or account level without modifying the IAM policies themselves. This makes Organizations a central control plane for permission boundaries across an entire AWS environment.

  • ✗

    AWS Single Sign-On

    Why it's wrong here

    AWS Single Sign-On, now called IAM Identity Center, centrally manages workforce identities and their assigned access to AWS accounts and business applications through SSO and permission sets, but it does not govern what those users can do to resources. The permission sets it creates map to IAM roles, but the actual fine-grained resource actions are still defined by IAM policies attached to those roles. It is an identity and assignment hub, not a service for centrally managing resource-level permissions across accounts.

  • ✓

    IAM Access Analyzer

    Why this is correct

    IAM Access Analyzer provides centralized visibility into resource-based policies across accounts by using external access analyzers to identify resources shared with external principals, including public access and cross-account access. It also includes policy generation and validation tools that help you craft least-privilege permissions based on actual usage. This enables security teams to proactively manage and reduce unintended access at scale, making it a key service for central access governance.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.