hardMultiple ChoiceObjective-mapped
CCSP Centralized Policy Practice Question
An organization has a cloud environment with many accounts. They want to prevent any account from using certain services that are not approved (e.g., outside of a defined list). What is the BEST way to enforce this at the organizational level?
⚠ Common exam trap
Candidates often confuse detective controls (like configuration monitoring) with preventive controls (like organizational governance policies), or assume that account-level access control policies can achieve the same centralized enforcement, missing the fact that organizational policies are the only mechanism that cannot be bypassed by account-level administrators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply a cloud governance policy at the organization level that denies the services.
Cloud governance policies at the organization level are the correct mechanism because they operate across all accounts, allowing centrally defined whitelists or blacklists of services. Unlike account-level access control policies, organizational policies set a permissions boundary that cannot be overridden by account administrators, ensuring that non-approved services are denied across the entire organization. This provides a preventive control that blocks the use of prohibited services before any action can occur.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure each account's access control policy to deny the services.
Why it's wrong here
Configuring each account's identity and access management policy can deny services, but it is not the best at the organizational level because each account administrator could potentially modify or bypass these policies. Centralized enforcement is more effective.
- ✗
Enable a cloud configuration monitoring service to detect and disable non-approved services.
Why it's wrong here
Configuration monitoring tools can detect non-approved services but are detective, not preventive. They cannot block usage; they can only alert or trigger remediation, which may not be immediate or guaranteed.
- ✓
Apply a cloud governance policy at the organization level that denies the services.
Why this is correct
Correct. A centralized policy operates at the organizational level, providing a preventive control that denies specified services across all accounts, and it cannot be overridden by individual account administrators.
- ✗
Use resource-specific access policies on each resource to restrict usage.
Why it's wrong here
Resource-based policies control access to specific resources, but they do not prevent accounts from using services altogether. They are applied per resource, not at the account or organizational level, and can be complex to manage at scale.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.