ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 441 - CLF-C02 discussion

Report
Export

A company wants to implement controls (guardrails) in a newly created AWS Control Tower landing zone.

Which AWS services or features can the company use to create and define these controls (guardrails)? (Select TWO.)

A.
AWS Config
Answers
A.
AWS Config
B.
Service control policies (SCPs)
Answers
B.
Service control policies (SCPs)
C.
Amazon GuardDuty
Answers
C.
Amazon GuardDuty
D.
AWS Identity and Access Management (1AM)
Answers
D.
AWS Identity and Access Management (1AM)
E.
Security groups
Answers
E.
Security groups
Suggested answer: A, B

Explanation:

AWS Config and service control policies (SCPs) are AWS services or features that the company can use to create and define controls (guardrails) in a newly created AWS Control Tower landing zone.

AWS Config is a service that enables users to assess, audit, and evaluate the configurations of their AWS resources. It can be used to create rules that check for compliance with the desired configurations and report any deviations. AWS Control Tower provides a set of predefined AWS Config rules that can be enabled as guardrails to enforce compliance across the landing zone1.

Service control policies (SCPs) are a type of policy that can be used to manage permissions in AWS Organizations. They can be used to restrict the actions that the users and roles in the member accounts can perform on the AWS resources. AWS Control Tower provides a set of predefined SCPs that can be enabled as guardrails to prevent access to certain services or regions across the landing zone2. Amazon GuardDuty is a service that provides intelligent threat detection and continuous monitoring for AWS accounts and resources. It is not a feature that can be used to create and define controls (guardrails) in a landing zone. AWS Identity and Access Management (IAM) is a service that allows users to manage access to AWS resources and services. It can be used to create users, groups, roles, and policies that control who can do what in AWS. It is not a feature that can be used to create and define controls (guardrails) in a landing zone. Security groups are virtual firewalls that control the inbound and outbound traffic for Amazon EC2 instances. They can be used to allow or deny access to an EC2 instance based on the port, protocol, and source or destination. They are not a feature that can be used to create and define controls (guardrails) in a landing zone.

asked 16/09/2024
Sorin Craia
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first