ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 445 - SAA-C03 discussion

Report
Export

A company uses AWS Organizations with all features enabled and runs multiple Amazon EC2 workloads in the ap-southeast-2 Region. The company has a service control policy (SCP) that prevents any resources from being created in any other Region. A security policy requires the company to encrypt all data at rest.

An audit discovers that employees have created Amazon Elastic Block Store (Amazon EBS) volumes for EC2 instances without encrypting the volumes. The company wants any new EC2 instances that any IAM user or root user launches in ap-southeast-2 to use encrypted EBS volumes. The company wants a solution that will have minimal effect on employees who create EBS volumes.

Which combination of steps will meet these requirements? (Select TWO.)

A.
In the Amazon EC2 console, select the EBS encryption account attribute and define a default encryption key.
Answers
A.
In the Amazon EC2 console, select the EBS encryption account attribute and define a default encryption key.
B.
Create an IAM permission boundary. Attach the permission boundary to the root organizational unit (OU). Define the boundary to deny the ec2:CreateVolume action when the ec2:Encrypted condition equals false.
Answers
B.
Create an IAM permission boundary. Attach the permission boundary to the root organizational unit (OU). Define the boundary to deny the ec2:CreateVolume action when the ec2:Encrypted condition equals false.
C.
Create an SCR Attach the SCP to the root organizational unit (OU). Define the SCP to deny the ec2:CreateVolume action when the ec2:Encrypted condition equals false.
Answers
C.
Create an SCR Attach the SCP to the root organizational unit (OU). Define the SCP to deny the ec2:CreateVolume action when the ec2:Encrypted condition equals false.
D.
Update the IAM policies for each account to deny the ec2:CreateVolume action when the ec2:Encrypted condition equals false.
Answers
D.
Update the IAM policies for each account to deny the ec2:CreateVolume action when the ec2:Encrypted condition equals false.
E.
In the Organizations management account, specify the Default EBS volume encryption setting.
Answers
E.
In the Organizations management account, specify the Default EBS volume encryption setting.
Suggested answer: C, E

Explanation:


asked 16/09/2024
Franco Santos
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first