Home › Certifications › AWS Certified Security SCS-C03 › Management and Security Governance
20 multiple-choice questions and 10 flashcards on Management and Security Governance, about 11% of the AWS Certified Security SCS-C03 bank. Every one carries a written rationale.
Management and Security Governance is one of 6 chapters in CoStudy's AWS Certified Security — Specialty (SCS-C03) bank, and it holds 20 of the bank's 178 multiple-choice questions — roughly 11% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
5 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
A regulated company wants to prevent employees in specific accounts from invoking generative AI foundation models entirely, enforced centrally at the AWS Organizations level rather than per-account IAM policy. Which SCS-C03 Domain 6 mechanism is named for this?
Answer: D — An AI service opt-out policy, applied at the Organizations level
A) A targeted SCP denying a specific API could work as a workaround, but it isn't the purpose-built policy type the exam guide names for this exact governance use case. B) Conformance packs are detective/after-the-fact, not a preventive centralized opt-out. C) Per-role boundaries don't scale centrally and must be maintained individually — the opposite of an Organizations-level control. D) Correct — the SCS-C03 exam guide names AI service opt-out policies specifically as an Organizations-level policy type for managing AI/ML service usage centrally.
An organization needs to ensure new accounts created in the Organization automatically have CloudTrail, Config, GuardDuty, and a baseline IAM setup. The MOST appropriate solution is:
Answer: D — SCP denying cloudtrail:StopLogging at org root
Control Tower Account Factory (and Customizations for Control Tower / AFT) is the canonical provisioning pattern. The others don't scale. D is the wrong service.
AWS Organizations Service Control Policies (SCPs) provide:
Answer: D — Deny-list ceiling on max permissions across
SCPs: account boundary. Restrict (not grant) what IAM users/roles can do in member accounts. Common: prevent disabling CloudTrail, restrict regions, prevent root API usage. Critical for multi-account governance.
Service Control Policies (SCPs) in AWS Organizations:
Answer: C — ENI, subnet, or VPC-level flow record capture
The relevant option: Defining behavior. Distractors) Each is incorrect.
AWS Artifact is the right service to:
Answer: D — Control Tower landing zone with guardrails
Artifact = AWS-side compliance docs portal. Common misconception that it generates customer compliance. The others are wrong.
3 cards from the 10 in this chapter.
AWS Audit Manager?
Continuous compliance evidence collection. Maps controls to frameworks.
AWS SCS-C03 exam structure?
65 questions (50 scored + 15 unscored), 170 minutes, $300. Pass at 750/1000. Compensatory scoring — no minimum per domain required.
Zero trust principles?
Never trust, always verify. Least privilege, MFA, micro-segmentation.
These are a sample. The full Management and Security Governance chapter runs 30 items with per-chapter progress tracking, on the web and in the iOS app.
Open AWS Certified Security SCS-C03 in CoStudy →