6.0 Security Foundations and Governance SCS-C03 Practice Quiz

84 exam-style questions covering 14% of the SCS-C03 exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the AWS Certified Security Specialty practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

A company is moving from independent AWS accounts to a governed multi-account environment. What should be established first?
  • A. Create an AWS Organizations structure with OUs aligned to security, production, development, and sandbox governance needs
  • B. Keep every account standalone and document the account list manually
  • C. Use one production account for every workload and team
  • D. Use only resource tags without inviting accounts into an organization

In this scenario, AWS Organizations deployment starts with an OU structure that matches governance boundaries and lets guardrails apply consistently.

A multi-account design uses one account for security tooling and another for log archive. Why is this useful?
  • A. It separates duties and protects audit evidence from workload account administrators
  • B. It lets application teams delete central logs more easily
  • C. It removes the need for any IAM policies
  • D. It forces every workload to use the management account

Here, AWS Organizations deployment benefits from specialized accounts that reduce privilege overlap and evidence tampering risk.

A security team wants to apply different guardrails to production and sandbox accounts. Which AWS Organizations design supports this?
  • A. Attach every policy directly to the management account only
  • B. Place accounts into separate OUs and attach policies at the appropriate OU level
  • C. Rely on account aliases to enforce guardrails
  • D. Use a shared IAM user to represent every account

Specifically, AWS Organizations deployment uses OU hierarchy to scope controls to accounts with similar risk and governance needs.

A security architect is defining OUs for regulated workloads. Which factor should drive OU placement?
  • A. Alphabetical order of account names only
  • B. Common control requirements, risk level, environment, and operational ownership
  • C. The number of EC2 instances in each account only
  • D. Dashboard color preferences from account owners

In this scenario, AWS Organizations deployment should group accounts so policies and baselines match real governance requirements.

A company has existing AWS Organizations accounts and wants to bring them under landing zone governance. What should be planned?
  • A. Delete all existing accounts and recreate them without migration analysis
  • B. Enroll accounts and OUs into AWS Control Tower after assessing guardrail and resource impact
  • C. Disable all logs before enrolling accounts
  • D. Move all existing workloads into the log archive account

Here, AWS Control Tower controls for existing environments require enrollment planning so controls do not unexpectedly disrupt workloads.

A company wants automated account creation with baseline controls. What AWS Organizations capability should be part of the design?
  • A. Manual account creation with no OU assignment until the first audit
  • B. Create accounts using personal email addresses for each developer
  • C. Account vending through an approved onboarding workflow that places accounts in the correct OU
  • D. Use a public spreadsheet as the account source of truth

Note that AWS Organizations deployment should make account creation repeatable and immediately attach the right governance scope.

A management account is used daily for experimentation and application hosting. What should be changed?
  • A. Grant every developer root access to the management account
  • B. Place all production data in the management account for convenience
  • C. Move workloads to member accounts and restrict the management account to organization administration
  • D. Disable organization-level audit logs to reduce noise

Specifically, AWS Organizations deployment should minimize management account usage because it has high-impact organization authority.

An acquired company has existing AWS accounts. What is an appropriate migration step into AWS Organizations?
  • A. Immediately attach the most restrictive SCP to every acquired account without testing
  • B. Move all workloads into the management account
  • C. Disable CloudTrail during account enrollment
  • D. Invite or migrate accounts into the organization after validating ownership, billing, and guardrail impact

AWS Organizations deployment for existing accounts should account for control impact and account ownership before enrollment.

Key Terms in This Domain

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/aws-security-specialty/security-foundations-and-governance/

<a href="https://quizbuffet.com/aws-security-specialty/security-foundations-and-governance/">AWS Security Specialty Security Foundations and Governance practice quiz on QuizBuffet</a>

Other SCS-C03 Domains

← Back to SCS-C03 practice test overview

Questions are written against the published SCS-C03 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.