CoStudy

HomeCertificationsAWS Certified Security SCS-C03 › Management and Security Governance

Management and Security Governance — AWS Certified Security SCS-C03 practice questions

20 multiple-choice questions and 10 flashcards on Management and Security Governance, about 11% of the AWS Certified Security SCS-C03 bank. Every one carries a written rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

What this chapter covers

Management and Security Governance is one of 6 chapters in CoStudy's AWS Certified Security — Specialty (SCS-C03) bank, and it holds 20 of the bank's 178 multiple-choice questions — roughly 11% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.

Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.

Free Management and Security Governance practice questions

5 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.

A regulated company wants to prevent employees in specific accounts from invoking generative AI foundation models entirely, enforced centrally at the AWS Organizations level rather than per-account IAM policy. Which SCS-C03 Domain 6 mechanism is named for this?

  1. An SCP explicitly denying bedrock:InvokeModel across all member accounts
  2. AWS Config conformance packs, flagging Bedrock usage after the fact for manual remediation
  3. IAM permission boundaries attached individually to every developer role
  4. An AI service opt-out policy, applied at the Organizations level

Answer: D — An AI service opt-out policy, applied at the Organizations level

A) A targeted SCP denying a specific API could work as a workaround, but it isn't the purpose-built policy type the exam guide names for this exact governance use case. B) Conformance packs are detective/after-the-fact, not a preventive centralized opt-out. C) Per-role boundaries don't scale centrally and must be maintained individually — the opposite of an Organizations-level control. D) Correct — the SCS-C03 exam guide names AI service opt-out policies specifically as an Organizations-level policy type for managing AI/ML service usage centrally.

An organization needs to ensure new accounts created in the Organization automatically have CloudTrail, Config, GuardDuty, and a baseline IAM setup. The MOST appropriate solution is:

  1. KMS alias without underlying key change
  2. Amazon Managed Blockchain without private channel
  3. Hardcoded credential in Lambda environment
  4. SCP denying cloudtrail:StopLogging at org root

Answer: D — SCP denying cloudtrail:StopLogging at org root

Control Tower Account Factory (and Customizations for Control Tower / AFT) is the canonical provisioning pattern. The others don't scale. D is the wrong service.

AWS Organizations Service Control Policies (SCPs) provide:

  1. Session policy scoped to single request
  2. Route 53 for identity federation
  3. IAM policy Allow with wildcard Resource
  4. Deny-list ceiling on max permissions across

Answer: D — Deny-list ceiling on max permissions across

SCPs: account boundary. Restrict (not grant) what IAM users/roles can do in member accounts. Common: prevent disabling CloudTrail, restrict regions, prevent root API usage. Critical for multi-account governance.

Service Control Policies (SCPs) in AWS Organizations:

  1. Third-party certificate imported to ACM
  2. SSM Parameter String plaintext value
  3. ENI, subnet, or VPC-level flow record capture
  4. IAM Roles Anywhere with X.509 trust anchor

Answer: C — ENI, subnet, or VPC-level flow record capture

The relevant option: Defining behavior. Distractors) Each is incorrect.

AWS Artifact is the right service to:

  1. IAM managed policy attached to group
  2. WAF for backend database queries
  3. Athena workgroup with encryption disabled
  4. Control Tower landing zone with guardrails

Answer: D — Control Tower landing zone with guardrails

Artifact = AWS-side compliance docs portal. Common misconception that it generates customer compliance. The others are wrong.

Management and Security Governance flashcards

3 cards from the 10 in this chapter.

AWS Audit Manager?

Continuous compliance evidence collection. Maps controls to frameworks.

AWS SCS-C03 exam structure?

65 questions (50 scored + 15 unscored), 170 minutes, $300. Pass at 750/1000. Compensatory scoring — no minimum per domain required.

Zero trust principles?

Never trust, always verify. Least privilege, MFA, micro-segmentation.

Practise the full chapter

These are a sample. The full Management and Security Governance chapter runs 30 items with per-chapter progress tracking, on the web and in the iOS app.

Open AWS Certified Security SCS-C03 in CoStudy →

Other AWS Certified Security SCS-C03 chapters

All AWS Certified Security SCS-C03 practice questions →