AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceEasy

A compliance team needs to ensure that all AWS accounts within their organization adhere to a strict policy that prevents the creation of any Amazon S3 bucket that allows public read or write access. This policy must be applied universally and prevent any user or role from overriding it. Which AWS service can enforce this preventive control across the entire organization?

  1. AAWS IAM policies applied to individual users and roles.
  2. BAWS Organizations Service Control Policies (SCPs).
  3. CAWS Config rules with automated remediation.
  4. DAmazon S3 Block Public Access settings at the account level.
Show answer & explanation

Correct answer: B. AWS Organizations Service Control Policies (SCPs).

AWS Organizations Service Control Policies (SCPs) allow you to centrally manage permissions for all accounts in your organization. An SCP can be used to explicitly deny S3 bucket creation or modification that would allow public read/write access, acting as a guardrail that no user or role in the affected accounts can override.

Why the other options are wrong

  • A. IAM policies are applied to individual identities or resources. While they can restrict users, an SCP provides a higher-level, organization-wide preventive control that even administrators in child accounts cannot bypass.
  • C. AWS Config detects non-compliance after it occurs and can remediate, but it's not a preventive control that stops the action from happening in the first place.
  • D. Amazon S3 Block Public Access settings are effective, but they are configured per account. An SCP can enforce this setting across all accounts in an organization.

AWS Organizations Service Control Policies (SCPs)

SCPs are JSON policies that specify the maximum permissions for members of an AWS Organization. They act as guardrails, preventing accounts from performing actions even if their IAM policies would otherwise allow them.

  • Applied at the OU or root level in AWS Organizations.
  • Preventive security control.
  • Cannot be overridden by IAM policies in member accounts.

Memory trick: SCPs: The Org's 'Big Boss' Rules, No Public S3 Allowed.

More Network Security, Compliance, and Governance questions