Skip to content
BytePatterns

SCS-C03 · Domain 6: Security Foundations and Governance · 14% of the exam

Task 6.1: Develop a strategy to centrally deploy and manage AWS accounts

Running many accounts from the top: Organizations and Control Tower with optional and custom controls, SCPs, RCPs, declarative and AI opt-out policies, delegated administrators for the security services, and central control of root user access and break-glass procedures.

Study it

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

An organization has turned on centralized root access, removed the root user credentials of its member accounts and not allowed password recovery for any of them. An engineer in a member account attached a bucket policy that denies every principal all S3 actions on a bucket, and now nobody can change or delete the policy. What should the security team do?

  1. ARecover the member account's root password by email and delete the policy as root
  2. BAttach an SCP to the member account that explicitly allows s3:DeleteBucketPolicy
  3. CRun the privileged root task that deletes the bucket policy from the management account
  4. DAttach a resource control policy that allows s3:DeleteBucketPolicy on the bucket
Show the answer and why
  • ARecover the member account's root password by email and delete the policy as root

    Incorrect

    With root credentials removed and account recovery not allowed, the member account cannot sign in as root or recover the password.

  • BAttach an SCP to the member account that explicitly allows s3:DeleteBucketPolicy

    Incorrect

    SCPs never grant permissions; they only set limits.

  • CRun the privileged root task that deletes the bucket policy from the management account

    Correct

    With centralized root access, the management account or IAM delegated administrator can perform privileged root tasks on a member account, including removing a misconfigured bucket policy.

  • DAttach a resource control policy that allows s3:DeleteBucketPolicy on the bucket

    Incorrect

    An RCP never grants permissions, so it cannot override the deny in the bucket policy.

Centralized root access replaces standing root credentials with short privileged tasks run from the management or delegated administrator account, such as unlocking a bucket policy that locks everyone out.

Question 2 · choose 1

A company must make sure that no principal outside its AWS organization can access objects in any S3 bucket in its member accounts, even if a bucket policy in a member account grants that access by mistake. Which control meets this requirement?

  1. AAn SCP that denies S3 actions unless aws:PrincipalOrgID is the organization ID
  2. BAn RCP that denies S3 access unless aws:PrincipalOrgID is the organization ID
  3. CS3 Block Public Access turned on for every account in the organization
  4. DAn AWS Config rule that flags bucket policies that allow outside accounts
Show the answer and why
  • AAn SCP that denies S3 actions unless aws:PrincipalOrgID is the organization ID

    Incorrect

    SCPs limit principals in the organization's member accounts. They do not affect principals from outside the organization.

  • BAn RCP that denies S3 access unless aws:PrincipalOrgID is the organization ID

    Correct

    RCPs restrict access to resources in member accounts, including by principals outside the organization, whatever the bucket policy allows.

  • CS3 Block Public Access turned on for every account in the organization

    Incorrect

    Block Public Access targets public grants. A bucket policy that names a specific outside account is not public and is not blocked.

  • DAn AWS Config rule that flags bucket policies that allow outside accounts

    Incorrect

    A Config rule detects the problem after it exists; it does not stop access.

SCPs bound what your principals can do; RCPs bound what can be done to your resources, by anyone. A data perimeter on resources needs RCPs.

Question 3 · choose 1

A company wants every account in its organization to block public sharing of AMIs and EBS snapshots. The setting must apply to new accounts as they join, must stay in force even when EC2 adds new APIs, and must also apply to actions taken by service-linked roles. Which control should the company use?

  1. AAn SCP that denies the EC2 API actions that make AMIs and snapshots public
  2. BAn AWS Config conformance pack that detects public AMIs and snapshots
  3. CA resource control policy that denies ec2 actions for principals outside the organization
  4. DAn EC2 declarative policy attached to the organization root
Show the answer and why
  • AAn SCP that denies the EC2 API actions that make AMIs and snapshots public

    Incorrect

    SCPs regulate access to specific API actions and do not govern service-linked roles, so new APIs and those roles fall outside it.

  • BAn AWS Config conformance pack that detects public AMIs and snapshots

    Incorrect

    Conformance packs evaluate and can remediate after the fact; they do not keep the configuration from being changed.

  • CA resource control policy that denies ec2 actions for principals outside the organization

    Incorrect

    RCPs limit access to resources by principals; they do not set an EC2 configuration and do not govern service-linked roles.

  • DAn EC2 declarative policy attached to the organization root

    Correct

    Declarative policies are enforced in the service's control plane, stay in force as the service adds APIs, apply to new accounts, and govern service-linked roles.

Declarative policies set a desired service configuration once for the organization. SCPs and RCPs authorize API calls, which leaves gaps when new APIs appear.

Question 4 · choose 1

A company runs development, test and production workloads in one AWS account. A mistake in development recently deleted a production resource. What does AWS recommend for separating these environments?

  1. ASeparate VPCs for each environment in the same account
  2. BSeparate AWS accounts grouped in organizational units
  3. CSeparate IAM users for each environment in the account
  4. DSeparate Regions for each environment in the account
Show the answer and why
  • ASeparate VPCs for each environment in the same account

    Incorrect

    VPCs separate networks, not IAM permissions or account-level limits.

  • BSeparate AWS accounts grouped in organizational units

    Correct

    Accounts act as isolation boundaries, and grouping them in OUs lets the company apply controls per environment.

  • CSeparate IAM users for each environment in the account

    Incorrect

    Users in the same account can still be granted access to each other's resources.

  • DSeparate Regions for each environment in the account

    Incorrect

    Many permissions and services are not separated by Region.

Multiple accounts also make cost, quotas and incident scope easier to manage.

Question 5 · choose 1

The security team wants to make sure that member accounts cannot remove themselves from the organization, which would free them from its SCPs. What should the team do?

  1. ATurn on MFA for each member account's root user
  2. BRemove the member accounts' alternate contacts
  3. CAn SCP that denies organizations:LeaveOrganization
  4. DTurn on all features only in the management account
Show the answer and why
  • ATurn on MFA for each member account's root user

    Incorrect

    MFA protects sign-in; it does not stop a permitted user from leaving.

  • BRemove the member accounts' alternate contacts

    Incorrect

    Contacts have nothing to do with leaving the organization.

  • CAn SCP that denies organizations:LeaveOrganization

    Correct

    Leaving requires organizations:LeaveOrganization, and the organization can apply a policy that removes that permission.

  • DTurn on all features only in the management account

    Incorrect

    All features is an organization-wide setting and does not block leaving by itself.

A removed account loses every organization policy, so blocking the exit protects all the other controls.

Question 6 · choose 1

A company created its organization only for consolidated billing. The Policies page shows that service control policies are not available. What must the company do first?

  1. AMove every account under a new root
  2. BEnable all features in the organization
  3. CBuy Enterprise Support for the management account
  4. DCreate an IAM policy named FullAWSAccess
Show the answer and why
  • AMove every account under a new root

    Incorrect

    An organization has one root; this does not enable SCPs.

  • BEnable all features in the organization

    Correct

    SCPs are available only in an organization that has all features enabled, not with consolidated billing alone.

  • CBuy Enterprise Support for the management account

    Incorrect

    Support plans do not control which policy types are available.

  • DCreate an IAM policy named FullAWSAccess

    Incorrect

    FullAWSAccess is an SCP that Organizations attaches once SCPs are enabled.

Enabling all features asks every member account to approve the change.

Question 7 · choose 1

An SCP attached to the organization root denies cloudtrail:StopLogging. An administrator in the management account still stops a trail there. Why did the SCP not prevent it?

  1. ASCPs never apply to CloudTrail actions
  2. BThe SCP must also be attached to each OU
  3. CThe administrator used the console instead of the API
  4. DSCPs do not apply in the management account
Show the answer and why
  • ASCPs never apply to CloudTrail actions

    Incorrect

    SCPs can deny CloudTrail actions in member accounts.

  • BThe SCP must also be attached to each OU

    Incorrect

    Attaching at the root already covers every member account.

  • CThe administrator used the console instead of the API

    Incorrect

    Console actions are API calls and are evaluated the same way.

  • DSCPs do not apply in the management account

    Correct

    SCPs affect only member accounts; they have no effect on the management account.

Keep workloads and broad permissions out of the management account, because SCPs cannot guard it.

Question 8 · choose 1

In an AWS Control Tower landing zone, the platform team wants users to create new accounts that are placed in a governed OU with its baseline applied. Which Control Tower feature provides this?

  1. AAccount Factory
  2. BAWS Artifact
  3. CThe Region deny control
  4. DDetective controls
Show the answer and why
  • AAccount Factory

    Correct

    Account Factory lets administrators and permitted users provision accounts in the landing zone into an OU with the baseline.

  • BAWS Artifact

    Incorrect

    Artifact provides compliance reports and agreements.

  • CThe Region deny control

    Incorrect

    Region deny limits Regions; it does not create accounts.

  • DDetective controls

    Incorrect

    Detective controls report noncompliance; they do not create accounts.

Account Factory can also apply customizations so new accounts start with the company's own settings.

Practise domain 6 →Practise all domains →