Courseiva
Security and Compliance →mediumMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no IAM users in any member account can create access keys for themselves. What is the MOST efficient way to enforce this policy across all accounts?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an SCP that denies the iam:CreateAccessKey action and attach it to the root organizational unit.

A service control policy (SCP) can be applied at the root or to specific OUs to deny IAM actions across all member accounts. Option A is correct because it centrally restricts the action. Option B is wrong because it only works for the master account. Option C is wrong because it requires individual account configuration. Option D is wrong because while AWS Config and Lambda can detect and remediate access key creation, this is a reactive approach and not the most efficient preventive control. SCPs proactively deny the action before it occurs, making them more efficient for enforcing this policy across all accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an SCP that denies the iam:CreateAccessKey action and attach it to the root organizational unit.

    Why this is correct

    An SCP is an organization-level policy that applies to all accounts (including the management account, though it can be excluded) when attached to the root OU. Denying iam:CreateAccessKey at the root OU is a preventive control that blocks the action organization-wide before it can be executed. This is the correct approach because it enforces the restriction in a centralized, scalable way that cannot be overridden by individual account IAM policies.

  • ✗

    Apply an IAM policy to the master account's root user that denies access key creation.

    Why it's wrong here

    An IAM policy attached to the management account's root user only affects that single principal. Member accounts have their own root users and IAM identities, and they are not governed by the management account's IAM policies. Therefore, this action would not prevent access key creation in any other AWS account in the organization, making it ineffective for the stated requirement.

  • ✗

    Enable AWS Trusted Advisor security checks and follow the recommendations.

    Why it's wrong here

    AWS Trusted Advisor provides recommendations and best-practice checks, but it is an advisory service, not an enforcement mechanism. It cannot block, deny, or automatically remediate access key creation. Following its recommendations requires manual action or custom automation, so it does not provide a preventive control against IAM access key creation across the organization.

  • ✗

    Use AWS Config to detect access key creation and automatically delete the keys using a Lambda function.

    Why it's wrong here

    AWS Config can detect resource changes, but it only records compliance and can trigger a Lambda function for reactive remediation. This approach is detective and corrective, meaning that a key is created before it is deleted, which leaves a window of exposure and relies on per-account setup. It is not a preventive guardrail like an SCP, which stops the action from occurring in the first place.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.