Service Control Policies Quiz

5 questions Pass: 70% +25 pts

Quiz covering Multi-Account AWS Environment

Service Control Policies Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    What is the primary purpose of a Service Control Policy (SCP) in an AWS Organizations environment?

  2. 2

    When an SCP is attached to an Organizational Unit (OU), which accounts are affected by the policy?

  3. 3

    If an IAM policy grants 's3:*' access but an SCP attached to the account explicitly denies 's3:DeleteBucket', what is the resulting permission?

  4. 4

    Which of the following statements is true regarding the 'FullAWSAccess' policy provided by AWS?

  5. 5

    You need to prevent accounts within a specific OU from disabling AWS CloudTrail in any region. What is the most effective way to achieve this using SCPs?