ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 459 - SAA-C03 discussion

Report
Export

A 4-year-old media company is using the AWS Organizations all features feature set fo organize its AWS accounts. According to he company's finance team, the billing information on the member accounts

must not be accessible to anyone, including the root user of the member accounts.

Which solution will meet these requirements?

A.
Add all finance team users to an IAM group. Attach an AWS managed policy named Billing to the group.
Answers
A.
Add all finance team users to an IAM group. Attach an AWS managed policy named Billing to the group.
B.
Attach an identity-based policy to deny access to the billing information to all users, including the root user.
Answers
B.
Attach an identity-based policy to deny access to the billing information to all users, including the root user.
C.
Create a service control policy (SCP) to deny access to the billing information. Attach the SCP to the root organizational unit (OU).
Answers
C.
Create a service control policy (SCP) to deny access to the billing information. Attach the SCP to the root organizational unit (OU).
D.
Convert from the Organizations all features feature set to the Organizations consolidated billing feature set.
Answers
D.
Convert from the Organizations all features feature set to the Organizations consolidated billing feature set.
Suggested answer: C

Explanation:

Service Control Policies (SCP): SCPs are an integral part of AWS Organizations and allow you to set fine-grained permissions on the organizational units (OUs) within your AWS Organization. SCPs provide central control over the maximum permissions that can be granted to member accounts, including the root user. Denying Access to Billing Information: By creating an SCP and attaching it to the root OU, you can explicitly deny access to billing information for all accounts within the organization. SCPs can be used to restrict access to various AWS services and actions, including billing-related services. Granular Control: SCPs enable you to define specific permissions and restrictions at the organizational unit level. By denying access to billing information at the root OU, you can ensure that no member accounts, including root users, have access to the billing information.

asked 16/09/2024
frederic Morteau
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first