AWS Certified DevOps Engineer – ProfessionalIncident and Event ResponseHard

A large enterprise uses a multi-account strategy with AWS Organizations. They need to ensure that specific security groups, which only allow inbound SSH (port 22) and RDP (port 3389) from a restricted corporate IP range, are never modified to allow wider access. Any attempt to change these security groups to permit access from '0.0.0.0/0' must be explicitly denied, even by root users, and an alert must be sent to the security team. Which AWS Organizations feature can enforce this preventative control?

  1. AAWS IAM Policies
  2. BAWS Systems Manager Automation
  3. CAWS Config Rules
  4. DService Control Policies (SCPs)
Show answer & explanation

Correct answer: D. Service Control Policies (SCPs)

Service Control Policies (SCPs) in AWS Organizations allow you to define the maximum available permissions for all IAM users and roles in affected accounts. They act as guardrails, preventing even root users from performing disallowed actions like modifying security groups to allow unrestricted access, and are effective across multiple accounts.

Why the other options are wrong

  • A. AWS IAM Policies define permissions for individual IAM users and roles within a single account. While they can restrict access, they cannot override permissions for the root user and are not centrally managed across an entire Organization for preventative guardrails like SCPs.
  • B. AWS Systems Manager Automation can be used for operational tasks and remediation, but it's not a preventative control that denies API calls at the Organizations level.
  • C. AWS Config Rules are detective controls; they detect non-compliance *after* a change has occurred. They can trigger remediation but cannot *prevent* the initial disallowed action.

AWS Organizations Service Control Policies (SCPs)

SCPs are JSON policies that specify the maximum permissions for all IAM users and roles in member accounts within an AWS Organization, acting as preventative guardrails.

  • Apply to all IAM users and roles, including the root user.
  • Prevent actions at the account level, even if an IAM policy grants them.
  • Used for central governance and compliance across multiple accounts.

Memory trick: SCPs are the ultimate security 'Stop' signs for your Organization.

More Incident and Event Response questions