Courseiva

SCS-C02 Management and Security Governance Practice Question

Which TWO of the following are valid methods to centrally manage security policies and enforce compliance across multiple AWS accounts? (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse AWS Security Hub's detection and aggregation capabilities with actual enforcement, but Security Hub does not automatically enforce compliance—it only reports findings, while conformance packs and SCPs provide the enforcement mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy AWS Config conformance packs using AWS CloudFormation StackSets across accounts.

AWS Config conformance packs provide a way to deploy a collection of AWS Config rules and remediation actions across multiple accounts and Regions. When combined with AWS CloudFormation StackSets, you can centrally deploy these conformance packs to all accounts in an AWS Organization, ensuring consistent compliance enforcement. This approach allows you to define and manage security policies as code, automatically evaluating resources against desired configurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy AWS Config conformance packs using AWS CloudFormation StackSets across accounts.

    Why this is correct

    AWS Config conformance packs are collections of AWS Config rules and remediation actions that can be deployed across multiple accounts and Regions using CloudFormation StackSets. This provides a centralized, repeatable way to enforce and monitor compliance baselines without needing to log into each account individually. The StackSet orchestrates the deployment, while the conformance pack defines the rules that evaluate resource compliance.

  • ✗

    Attach IAM policies to all IAM users in each account.

    Why it's wrong here

    IAM policies are scoped to a single account and individual identities; there is no native mechanism to propagate them across accounts in an organization. Attaching policies to every IAM user is operationally inefficient and does not enforce compliance at the resource or service level. Central compliance management requires account-level guardrails such as SCPs or AWS Config rules, not per-user permission documents.

  • ✗

    Use AWS Security Hub to automatically enforce compliance rules.

    Why it's wrong here

    AWS Security Hub aggregates security findings and performs consolidated compliance checks across accounts, but it is a visibility and prioritization tool, not an enforcement mechanism. It does not automatically remediate or block non-compliant resources; it relies on integrations such as EventBridge rules or AWS Systems Manager Automation to trigger corrective action. Therefore, Security Hub alone cannot centrally enforce compliance rules.

  • ✓

    Use AWS Organizations service control policies (SCPs) to restrict allowed actions.

    Why this is correct

    Service control policies (SCPs) are centrally managed in AWS Organizations and apply a permission guardrail to all principals in attached accounts, OUs, or the entire organization. They define the maximum allowed actions and cannot be overridden by the account's own IAM policies, making them a powerful mechanism for central restriction. SCPs are a valid method for enforcing compliance because they can limit root-level permissions across the organization.

  • ✗

    Enable VPC Flow Logs in each account and send them to a central S3 bucket.

    Why it's wrong here

    VPC Flow Logs capture network traffic metadata such as source and destination IPs, ports, and protocols, and can be streamed to a central S3 bucket for aggregation. This provides audit visibility and can support detective controls, but it does not enforce or restrict any actions. Centralizing flow logs is a logging practice, not a compliance enforcement method, because it has no ability to alter resource behavior.

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.