Courseiva
Security and Compliance →hardMultiple Select

SOA-C02 Security and Compliance Practice Question

A company uses AWS Organizations and wants to restrict the use of specific AWS services across all member accounts. Which TWO methods can be used to enforce these restrictions? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create IAM policies in each account that deny the service actions and attach them to all IAM users and roles.

IAM policies in each account can deny actions for specific services, and when attached to all IAM users and roles, they effectively restrict usage across the account, though this requires consistent application. Option D is correct because SCPs attached to the root organizational unit can deny access to specified services across all member accounts in the organization. Option B is incorrect because AWS Config rules can detect non-compliance but cannot enforce restrictions or disable services. Option C is incorrect because AWS Service Catalog is used to create and manage a catalog of approved services, not to block disallowed services. Option E is incorrect because VPC endpoints control network traffic to services, not service-level restrictions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create IAM policies in each account that deny the service actions and attach them to all IAM users and roles.

    Why this is correct

    IAM policies can explicitly deny AWS service actions and, when attached to every IAM user and role in an account, prevent those principals from invoking the disallowed APIs. However, this approach is operationally heavy because you must attach the policy to all existing and future principals individually, and it does not restrict the account root user unless combined with an SCP or resource-based policy. It is a valid account-level enforcement method, but it requires diligent maintenance across all accounts.

  • ✗

    Use AWS Config rules to automatically disable non-compliant services.

    Why it's wrong here

    AWS Config rules are designed to evaluate resource configurations against desired policies and can detect when a resource is non-compliant, such as an instance using an unauthorized service. Config can trigger automated remediation through Systems Manager Automation, but it cannot disable or block service APIs in real time. It works reactively after a resource exists, not proactively to deny a principal from calling a service action, so it is not an access control mechanism.

  • ✗

    Use AWS Service Catalog to block the use of disallowed services.

    Why it's wrong here

    AWS Service Catalog is a service for managing an approved catalog of IT services that users can provision, such as EC2 instances or databases, via products and portfolios. It governs which pre-defined templates end users can launch, but it does not have the ability to deny or block access to AWS service APIs themselves. Service Catalog is a provisioning governance tool, not an authorization policy engine, so it cannot restrict the use of disallowed services across an account.

  • ✓

    Attach a service control policy to the root organizational unit that denies the service actions.

    Why this is correct

    Attaching a service control policy (SCP) to the root organizational unit applies the policy to all accounts within that OU, and SCPs can explicitly deny specific service actions for every principal, including the root user. SCPs act as a permission guardrail that limits the maximum permissions available to all IAM principals in the account, and they cannot be overridden by IAM allow policies. This is the most scalable and comprehensive method for restricting services across an AWS Organization, as it requires no individual IAM policy attachments.

  • ✗

    Configure VPC endpoints to block traffic to the disallowed services.

    Why it's wrong here

    VPC endpoints provide private network connectivity from a VPC to AWS services, but they do not govern authorization to call service APIs. Requests sent through a VPC endpoint are still evaluated by IAM and resource-based policies, so a service action is denied based on permissions, not the network path. Moreover, VPC endpoints only affect traffic originating within the associated VPC; they do not control API calls made from outside the VPC, such as from the public internet, on-premises networks, or other accounts, so they cannot block access to disallowed services.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.