Courseiva
Security and Compliance →easyMultiple Choice

SOA-C02 Security and Compliance Practice Question

An organization wants to centrally manage access to multiple AWS accounts in an AWS Organizations setup. Which AWS service should the SysOps administrator use to define and enforce fine-grained permissions across accounts?

⚠ Common exam trap

Many exam-takers confuse Service Control Policies (SCPs) with fine-grained permission enforcement, but SCPs only set guardrails and cannot grant cross-account access or define granular user-level permissions, which is the core requirement of this question.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IAM roles with cross-account trust policies

IAM roles with cross-account trust policies allow a SysOps administrator to define fine-grained permissions centrally in a single AWS account (the management or security account) and then grant access to users or services in other accounts by assuming the role. This approach uses AWS Security Token Service (STS) to issue temporary credentials, enabling precise control over actions and resources across accounts without duplicating IAM users or policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Config rules

    Why it's wrong here

    AWS Config rules evaluate recorded resource configurations against a set of desired compliance policies, such as checking whether S3 buckets have encryption enabled. They do not issue API calls that grant or deny access, and they cannot create or alter IAM roles or trust relationships. While AWS Config can trigger auto-remediation via Systems Manager, that is a reactive fix for noncompliant resources, not a central access-control mechanism.

  • ✗

    Service control policies (SCPs)

    Why it's wrong here

    Service control policies act as an outer guardrail at the AWS Organizations root, OU, or account level, limiting the maximum permissions that IAM principals can use. They never grant a permission; they only deny or allow permissions that are already present in the identity- or resource-based policies. Because they cannot define fine-grained actions like 'read one S3 object' or 'write to a specific DynamoDB table,' they are unsuitable for centrally managing detailed cross-account access.

  • ✓

    IAM roles with cross-account trust policies

    Why this is correct

    IAM roles are the correct mechanism because a role in a target account can attach a permissions policy that precisely defines allowable actions and resources, and a trust policy in the same role lists which principals in a central account may assume it. When a user in the central account calls sts:AssumeRole, AWS returns temporary, scoped credentials that carry exactly the role's permissions, no more and no less. This gives fine-grained control while centralizing the decision about who gets to assume which role.

  • ✗

    AWS Single Sign-On (SSO)

    Why it's wrong here

    AWS Single Sign-On (now IAM Identity Center) primarily focuses on authenticating users across an organization and presenting a user portal for access, not on authoring resource-level permissions. Although SSO permission sets contain policy documents that ultimately map to IAM roles, those roles are created and managed under the hood; fine-grained access decisions are still enforced by IAM role policies. Thus, for directly defining and controlling granular cross-account permissions, the fundamental building block is the IAM role itself.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.