Service Control Policies Quiz

5 questions Pass: 70% +25 pts

Quiz covering IAM Policies and Permissions

Service Control Policies Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    What is the primary purpose of a Service Control Policy (SCP) in an AWS Organizations environment?

  2. 2

    If an SCP denies access to the 's3:DeleteBucket' action, but an IAM policy explicitly allows it, what is the resulting effect?

  3. 3

    An administrator wants to restrict all accounts in an Organizational Unit (OU) from using specific AWS regions. Which policy type is best suited for this?

  4. 4

    When attaching an SCP to the root of an AWS Organization, who is affected by the policy?

  5. 5

    You have an SCP that uses an 'Allow' statement for EC2 actions and no other statements. What is the effective permission for an IAM user who has an IAM policy allowing S3 access but no EC2 access?