Courseiva
hardMultiple ChoiceObjective-mapped

CCSP Centralized Policy Practice Question

An organization has a cloud environment with many accounts. They want to prevent any account from using certain services that are not approved (e.g., outside of a defined list). What is the BEST way to enforce this at the organizational level?

⚠ Common exam trap

Candidates often confuse detective controls (like configuration monitoring) with preventive controls (like organizational governance policies), or assume that account-level access control policies can achieve the same centralized enforcement, missing the fact that organizational policies are the only mechanism that cannot be bypassed by account-level administrators.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Apply a cloud governance policy at the organization level that denies the services.

Cloud governance policies at the organization level are the correct mechanism because they operate across all accounts, allowing centrally defined whitelists or blacklists of services. Unlike account-level access control policies, organizational policies set a permissions boundary that cannot be overridden by account administrators, ensuring that non-approved services are denied across the entire organization. This provides a preventive control that blocks the use of prohibited services before any action can occur.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure each account's access control policy to deny the services.

    Why it's wrong here

    Configuring each account's identity and access management policy can deny services, but it is not the best at the organizational level because each account administrator could potentially modify or bypass these policies. Centralized enforcement is more effective.

  • Enable a cloud configuration monitoring service to detect and disable non-approved services.

    Why it's wrong here

    Configuration monitoring tools can detect non-approved services but are detective, not preventive. They cannot block usage; they can only alert or trigger remediation, which may not be immediate or guaranteed.

  • Apply a cloud governance policy at the organization level that denies the services.

    Why this is correct

    Correct. A centralized policy operates at the organizational level, providing a preventive control that denies specified services across all accounts, and it cannot be overridden by individual account administrators.

  • Use resource-specific access policies on each resource to restrict usage.

    Why it's wrong here

    Resource-based policies control access to specific resources, but they do not prevent accounts from using services altogether. They are applied per resource, not at the account or organizational level, and can be complex to manage at scale.

About these practice questions

This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.