Service Control Policies Quiz

5 questions Pass: 70% +25 pts

Quiz covering Secure Access

Service Control Policies Quiz

5 questions | Pass: 70% | Earn 25 points

Questions in this quiz

A preview of the 5 questions covered. Start the quiz above to answer them, check your score, and read the explanations.

  1. 1

    What is the primary purpose of a Service Control Policy (SCP) in a multi-account cloud environment?

  2. 2

    If an IAM policy grants 'S3:FullAccess' but an applied SCP contains an explicit 'Deny' for the S3 service, what is the resulting effective permission?

  3. 3

    Which of the following best describes the inheritance behavior of SCPs when applied to an Organizational Unit (OU)?

  4. 4

    You want to restrict all accounts in your organization to only use specific AWS regions. How should you implement this using SCPs?

  5. 5

    An SCP is attached to an OU that contains an account with an IAM user who has an 'AdministratorAccess' managed policy. If the SCP contains a 'Deny' for 'iam:DeleteRole', can the administrator delete a role?