Service Control Policies Quiz

5 questions Pass: 70% +25 pts

Quiz covering Multi-Account Management

Service Control Policies Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    What is the primary purpose of Service Control Policies (SCPs) in an AWS Organization?

  2. 2

    If an SCP is attached to an Organizational Unit (OU) and a different SCP is attached to an account within that OU, how are the permissions evaluated?

  3. 3

    You want to prevent all users in a specific development account from deleting S3 buckets, regardless of their IAM permissions. What is the most effective way to do this using SCPs?

  4. 4

    Which of the following statements regarding the 'FullAWSAccess' policy is true?

  5. 5

    You have an SCP that uses an Allow statement for 'ec2:*' and 's3:*'. A user in the affected account has an IAM policy that allows 'ec2:RunInstances' and 'iam:CreateUser'. What can the user perform?