Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company is using AWS Organizations with SCPs to restrict access to services. The security team wants to ensure that no IAM user can create access keys, but the SCP is not working as expected. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SCP is applied to a member account, but the IAM user is in the management account.

SCPs apply only to member accounts, not the management account. If the IAM user is in the management account, the SCP cannot restrict their actions. Option A is incorrect because SCPs are inherited from the root OU to all member accounts, so the SCP would be applied if the account were a member account; the issue is that the user is in the management account. Option C is wrong because SCPs take effect almost immediately, not 24 hours. Option D is wrong because SCPs apply to all principals (including IAM users) in member accounts, not just root users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SCP is applied to the root OU but not inherited by the account.

    Why it's wrong here

    Service control policies (SCPs) attached to any OU are inherited by every OU and account directly or indirectly under that OU. Attaching an SCP to the root OU applies it to all member accounts in the organization, so the account would indeed be subject to its restrictions. This option incorrectly claims that inheritance does not happen, which contradicts the core hierarchy of AWS Organizations.

  • ✓

    The SCP is applied to a member account, but the IAM user is in the management account.

    Why this is correct

    SCPs act as a permission boundary for member accounts, but they have no effect on the management account (also known as the payer account) in AWS Organizations. IAM users and roles in the management account retain their full permissions even if an SCP is attached to a member account. Therefore, if the IAM user resides in the management account, the SCP applied to the member account cannot possibly restrict that user's access, making this the correct explanation.

  • ✗

    The SCP has a Deny effect, but it takes 24 hours to apply.

    Why it's wrong here

    SCP changes in AWS Organizations propagate and take effect within a few minutes, not 24 hours. There is no built-in propagation delay for SCPs; once you attach or update a policy, the new restrictions apply almost immediately to the target accounts. The 24-hour figure is a misconception, likely conflated with AWS Config conformance pack updates or other services, and does not apply to SCPs.

  • ✗

    The SCP only applies to root users, not IAM users.

    Why it's wrong here

    SCPs apply to all IAM users, IAM roles, and the root user of every member account in the organization. They operate at the account level as an upper permissions guardrail, meaning they limit the maximum permissions that any principal in that account can obtain, including IAM users. Thus, the notion that SCPs only affect root users is fundamentally incorrect—IAM users are subject to the same restrictions as long as they are in a member account.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.