AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceMedium
A company uses AWS Organizations to manage multiple member accounts. The security team wants to prevent any account in the 'Sandbox' organizational unit from disabling AWS CloudTrail, regardless of the IAM permissions granted within those accounts. What should the security team implement?
- AAn IAM policy attached to each user in the Sandbox accounts
- BAn AWS Config rule that alerts when CloudTrail is disabled
- CA CloudTrail resource policy applied only to the management account
- DA Service Control Policy (SCP) attached to the Sandbox OU that denies the CloudTrail stop/delete actions
Show answer & explanationAnswer & explanation
Correct answer: D. A Service Control Policy (SCP) attached to the Sandbox OU that denies the CloudTrail stop/delete actions
Service Control Policies (SCPs) in AWS Organizations set permission guardrails at the OU or account level that apply to all IAM users and roles within those accounts, even overriding permissions granted by local IAM policies, making them ideal for enforcing organization-wide restrictions like preventing CloudTrail from being disabled.
Why the other options are wrong
- A. Individual IAM policies could be bypassed by an account admin with sufficient permissions elsewhere.
- B. An AWS Config rule only detects and alerts on the issue but does not prevent the action.
- C. CloudTrail itself doesn't use resource policies in this way for cross-account restriction.
Service Control Policy (SCP)
A policy in AWS Organizations that sets the maximum available permissions for accounts within an OU, acting as a guardrail that overrides local IAM permissions.
- Applied at OU or account level in AWS Organizations
- Does not grant permissions, only restricts maximum allowed actions
- Cannot be overridden by IAM policies within the account
Memory trick: SCPs are the org-wide 'ceiling' no IAM policy can break through.