Service Control Policies Quiz
Quiz covering IAM Policies
Service Control Policies Quiz
5 questions | Pass: 70% | Earn 25 points
Questions in this quiz
A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.
- 1
What is the primary purpose of a Service Control Policy (SCP) in AWS Organizations?
- 2
If an SCP denies access to a specific service, but an IAM policy explicitly allows it, what is the resulting effective permission?
- 3
Which of the following is true regarding SCPs applied to the Management (Root) account of an AWS Organization?
- 4
You want to restrict all member accounts in your organization to only use specific AWS regions. Which policy type should you use?
- 5
An SCP is attached to an Organizational Unit (OU) with a 'FullAWSAccess' policy. A child OU is created with a new SCP that denies access to Amazon S3. What is the effective permission for an account inside the child OU?
- Amazon GuardDuty Configuration
- Amazon GuardDuty Configuration Quiz5q
- GuardDuty Runtime Monitoring
- GuardDuty Runtime Monitoring Quiz5q
- Security Hub Aggregation
- Security Hub Aggregation Quiz5q
- AWS Security Finding Format (ASFF)
- AWS Security Finding Format (ASFF) Quiz5q
- Amazon Inspector Scanning
- Amazon Inspector Scanning Quiz5q
Enjoying the courses?
Everything stays free. Pro shows fewer ads, doubles the points you earn on every lesson and quiz so you progress twice as fast, unlocks half of every practice exam — plus full case studies — with the Learn & Exam study modes, and lets you read each lesson on one page.
- ✓ Fewer advertisements
- ✓ 2× points per lesson & quiz
- ✓ 50% of every exam unlocked
- ✓ Learn & Exam modes
- ✓ Distraction-free lessons