Courseiva
Security and Compliance →hardMultiple Choice

SOA-C02 Security and Compliance Practice Question

A company uses AWS Organizations with SCPs to restrict member accounts. The security team wants to prevent all users in the 'Developers' OU from deleting S3 buckets, except for the root user of the management account. How should this be implemented?

⚠ Common exam trap

The trap is thinking SCPs can be conditioned to exempt the root user or that member-account root users are exempt — SCPs do not apply to the management account at all, and they do apply to member account roots.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Attach an SCP that denies s3:DeleteBucket to the Developers OU. The management account root is not affected by SCPs.

SCPs applied to an OU restrict what member accounts can do, but they do not affect the management account. The management account root user is not constrained by SCPs, so attaching a deny s3:DeleteBucket SCP to the Developers OU prevents users in that OU from deleting buckets while leaving the management account root unaffected. This matches the requirement exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an IAM policy that denies s3:DeleteBucket and attach it to all IAM users. The root user is not affected by IAM policies.

    Why it's wrong here

    An IAM policy denying s3:DeleteBucket attached to all IAM users creates restrictions only for those IAM identities, but the account root user is not bound by IAM policies. The root user retains full administrative access and can still delete S3 buckets. This approach also fails to cover service roles, federated users, or other principals that are not explicitly attached, making it an inconsistent organization-wide control.

  • ✓

    Attach an SCP that denies s3:DeleteBucket to the Developers OU. The management account root is not affected by SCPs.

    Why this is correct

    Attaching an SCP that denies s3:DeleteBucket to the Developers OU effectively blocks all principals in every member account under that OU, including each member account's root user, because SCPs act as an upper permission boundary. The management account root is explicitly exempt from SCP restrictions, so this control does not affect the management account root. This is the correct way to implement a cross-account deletion guardrail.

  • ✗

    Attach an SCP that denies s3:DeleteBucket except when called by root user.

    Why it's wrong here

    An SCP cannot include a condition that exempts the root user because SCPs contain a Statement with Effect, Action, Resource, and Condition, but they lack a Principal element — they apply uniformly to all principals in the affected accounts. There is no supported mechanism in SCP syntax to say 'except when called by root user,' and the member account root user is just as subject to the SCP as any IAM role. Attempting to add such a condition would either be invalid or ineffective.

  • ✗

    Attach an SCP that denies s3:DeleteBucket to the Developers OU. The root user in member accounts is not affected.

    Why it's wrong here

    The final clause of this option is factually backwards: SCPs attached to an OU apply to every principal in member accounts, including the member account root user. The root user in a member account is not exempt from SCPs, even though it is exempt from IAM policies. Therefore, this option's claimed limitation is incorrect; the SCP would actually affect the root user, which is necessary for preventing bucket deletion.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.