AWS Organizations lets you manage many AWS accounts as one. You group accounts, apply guardrails from the top, and consolidate billing — the standard way large companies keep dozens of accounts under control.
The two things the exam tests
Service Control Policies (SCPs) set the maximum permissions any account (and its IAM users) can have — guardrails that even account admins can’t exceed. Consolidated billing rolls all accounts into one bill and can unlock volume discounts. Question about restricting what whole accounts can do? SCPs.
Test yourself
A company must guarantee that no one in certain member accounts can ever use services outside approved Regions, regardless of their IAM permissions. What enforces this?
- An IAM policy in each account
- A Service Control Policy (SCP) in AWS Organizations
- A security group rule
- A bucket policy
👉 Click to reveal the answer & explanation
Correct answer: B. An SCP sets the permission ceiling for entire accounts, so even account admins can’t exceed it — ideal for Region restrictions. IAM policies (A) can be changed by account admins; security groups (C) and bucket policies (D) control narrow resources, not account-wide service use.
Related topics
AWS IAM · AWS CloudTrail · Shared Responsibility Model
Ready to pass your AWS exam?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026