Attach an SCP that denies service access to the member-account root user

Answer Correct answer: A — an SCP that explicitly denies service access by the member-account root user protects the account even if root credentials are compromised.

A company has many member accounts in an organization in AWS Organizations. The company is concerned about the potential for misuse of the AWS account root user credentials for member accounts in the organization. To address this potential misuse, the company wants to ensure that even if the account root user credentials are compromised the account is still protected. Which solution will meet this requirement?

  1. Block service access by using SCPs for the root user Correct Answer
  2. Remove the password for the root user
  3. Delete access keys for the root user
  4. Create an Amazon EventBridge rule to detect any AWS account root user API events

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

An SCP with an explicit deny bound to the root user is the only control that actively prevents root-user actions org-wide; root cannot detach or override an SCP because SCPs sit above identity-based policies. EventBridge detection (D) only alerts after the fact; removing the password (B) or deleting access keys (C) reduces exposure but is not centrally enforced and does not stop a compromised root from other vectors.

To protect member accounts even if root credentials are compromised, attach an SCP to the OU that uses an explicit deny on the root user's actions (e.g., a deny on all services for the root-user principal). SCPs are evaluated above all other policies and cannot be overridden—even by the root user—so the compromised root user loses its effective permissions.

Choosing EventBridge detection (D)—it notifies that root was used but does not prevent misuse. Deleting access keys (C) or removing the password (B) helps but is per-account, manual, and incomplete (root can still assume roles or reset MFA); an SCP guardrail is centrally enforced and comprehensive.

Community Discussion (4 comments)

phmeeeee 👍 1 Selected: A
it is explicit deny at the SCP-level, SCP is supreme control the power! no one can override even the root user
navid1365 👍 2 Selected: A
A is correct. D enables identifying that the root account has been used, but does not prevent.
aescudero51 👍 3 Selected: A
A https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examples_general.html#example-scp-root-user
Zek 👍 1
A https://www.examtopics.com/discussions/amazon/view/111064-exam-aws-certified-security-specialty-topic-1-question-502/

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

An SCP attached to the organization/OU with an explicit deny on the root user's service actions is evaluated above every other policy and cannot be overridden by anyone in the account, including the root user. This means even a compromised root-user credential has no effective permissions, directly meeting the 'protected even if compromised' requirement.

Why the Other Options Are Wrong

D (EventBridge rule) only detects and alerts that root was used; it does nothing to prevent the action. B (remove root password) and C (delete root access keys) reduce some exposure but are manual, per-account, and leave other root vectors open; they are not centrally enforced guardrails. A is the preventive control.

Community Comment Notes

Community voted A (100). Commenters noted the SCP is an explicit deny at the org level that even root cannot override. D was described as detection-only, not prevention. A is confirmed via the Organizations SCP root-user example doc.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide