ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 182 - SAA-C03 discussion

Report
Export

A security team wants to limit access to specific services or actions in all of the team's AWS accounts.

All accounts belong to a large organization in AWS Organizations. The solution must be scalable and there must be a single point where permissions can be maintained.

What should a solutions architect do to accomplish this?

A.
Create an ACL to provide access to the services or actions.
Answers
A.
Create an ACL to provide access to the services or actions.
B.
Create a security group to allow accounts and attach it to user groups.
Answers
B.
Create a security group to allow accounts and attach it to user groups.
C.
Create cross-account roles in each account to deny access to the services or actions.
Answers
C.
Create cross-account roles in each account to deny access to the services or actions.
D.
Create a service control policy in the root organizational unit to deny access to the services or actions.
Answers
D.
Create a service control policy in the root organizational unit to deny access to the services or actions.
Suggested answer: D

Explanation:

Service control policies (SCPs) are one type of policy that you can use to manage your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization, allowing you to ensure your accounts stay within your organization's access control guidelines. See https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scp.html.

asked 16/09/2024
Daniel Calleja
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first