Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Service Control Policy (SCP) Practice Question

A company uses AWS Organizations with multiple accounts. The security team wants to enforce that all IAM users in member accounts must use MFA. They create an SCP that denies all actions if the IAM user does not have MFA. However, the SCP does not apply to the root user. The SysOps administrator finds that some IAM users in member accounts are still able to access the console without MFA. What is the most likely reason?

⚠ Common exam trap

The trap is assuming SCPs are global once created, when in fact they only affect accounts within the OU they are attached to — attachment scope is the most common reason an SCP appears not to work.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SCP is applied to an OU that does not contain the affected accounts.

SCPs are inherited down the OU tree, but they only apply to accounts within the OU they are attached to. If the SCP is attached to an OU that does not contain the affected member accounts, those accounts are unaffected and their IAM users can still sign in without MFA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The SCP is applied to an OU that does not contain the affected accounts.

    Why this is correct

    Service control policies take effect only on accounts that are directly in the OU or in child OUs underneath it. If the affected accounts are in a different OU—or in the organization root with no explicit SCP attachment—the deny statement won't apply. The fix is to attach the denying SCP to the exact branch of the organization hierarchy that contains those accounts, which requires verifying the OU structure in AWS Organizations.

  • ✗

    The IAM user has a resource-based policy that allows access.

    Why it's wrong here

    A resource-based policy can grant permissions to an IAM user, but it cannot override an explicit deny from a service control policy. In AWS, SCPs act as absolute account-level guardrails, and the effective permission set is the intersection of the SCP, identity-based policies, and resource-based policies. Because the SCP explicitly denies the action, any allowance from a resource policy is suppressed for all principals in the account, making this answer incorrect.

  • ✗

    The SCP only applies to the root user, not IAM users.

    Why it's wrong here

    This is a common misconception: service control policies apply to every principal in the account, including IAM users, IAM roles, and the root user. SCPs do not differentiate between root and IAM principals; they define the maximum allowed actions for the entire account within the organization. Therefore, if the SCP contains a Deny for a service action, that action is blocked for all identities, so this statement does not explain why access is still possible.

  • ✗

    The SCP is not inherited by child OUs.

    Why it's wrong here

    In AWS Organizations, SCPs attached to the root or a parent OU are inherited by all child OUs and their accounts. The policy hierarchy is cumulative—effective SCPs are the union/inheritance of all policies along the path from the root to the account, meaning a parent-level Deny continues to constrain accounts in child OUs. Since the affected account would still be subject to the inherited SCP, lack of inheritance cannot be the reason for the issue, so this answer is incorrect.

About these practice questions

One of 1,169 original SOA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.