hardMultiple Choice
CCSP Centralized Policy Practice Question
An organization has a cloud environment with many accounts. They want to prevent any account from using certain services that are not approved (e.g., outside of a defined list). What is the BEST way to enforce this at the organizational level?
⚠ Common exam trap
Candidates often confuse detective controls (like configuration monitoring) with preventive controls (like organizational governance policies), or assume that account-level access control policies can achieve the same centralized enforcement, missing the fact that organizational policies are the only mechanism that cannot be bypassed by account-level administrators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a cloud governance policy at the organization level that denies the services.
Cloud governance policies at the organization level are the correct mechanism because they operate across all accounts, allowing centrally defined whitelists or blacklists of services. Unlike account-level access control policies, organizational policies set a permissions boundary that cannot be overridden by account administrators, ensuring that non-approved services are denied across the entire organization. This provides a preventive control that blocks the use of prohibited services before any action can occur.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure each account's access control policy to deny the services.
Why it's wrong here
Configuring each account's identity and access management policy can deny services, but it is not the best at the organizational level because each account administrator could potentially modify or bypass these policies. Centralized enforcement is more effective.
- ✗
Enable a cloud configuration monitoring service to detect and disable non-approved services.
Why it's wrong here
A monitoring service only detects non-approved service usage after the fact and cannot prevent accounts from launching those services. It is tempting because detection and remediation feel like enforcement, and it would be the correct choice for visibility and alerting rather than organisation-wide prevention.
- ✓
Apply a cloud governance policy at the organization level that denies the services.
Why this is correct
An organisation-level governance policy applies a deny rule across every account, blocking unapproved services regardless of individual account configuration. This satisfies the requirement to enforce the approved-service list centrally, rather than relying on per-account controls that could be bypassed or missed.
- ✗
Use resource-specific access policies on each resource to restrict usage.
Why it's wrong here
Resource-based policies control access to specific resources, but they do not prevent accounts from using services altogether. They are applied per resource, not at the account or organizational level, and can be complex to manage at scale.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.