ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 660 - SAA-C03 discussion

Report
Export

A company has an organization in AWS Organizations. The company runs Amazon EC2 instances across four AWS accounts in the root organizational unit (OU). There are three nonproduction accounts and one production account. The company wants to prohibit users from launching EC2 instances of a certain size in the nonproduction accounts. The company has created a service control policy (SCP) to deny access to launch instances that use the prohibited types.

Which solutions to deploy the SCP will meet these requirements? (Select TWO.)

A.
Attach the SCP to the root OU for the organization.
Answers
A.
Attach the SCP to the root OU for the organization.
B.
Attach the SCP to the three nonproduction Organizations member accounts.
Answers
B.
Attach the SCP to the three nonproduction Organizations member accounts.
C.
Attach the SCP to the Organizations management account.
Answers
C.
Attach the SCP to the Organizations management account.
D.
Create an OU for the production account. Attach the SCP to the OU. Move the production member account into the new OU.
Answers
D.
Create an OU for the production account. Attach the SCP to the OU. Move the production member account into the new OU.
E.
Create an OU for the required accounts. Attach the SCP to the OU. Move the nonproduction member accounts into the new OU.
Answers
E.
Create an OU for the required accounts. Attach the SCP to the OU. Move the nonproduction member accounts into the new OU.
Suggested answer: B, E

Explanation:

SCPs are a type of organization policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization.SCPs help you to ensure your accounts stay within your organization's access control guidelines1.

To apply an SCP to a specific set of accounts, you need to create an OU for those accounts and attach the SCP to the OU. This way, the SCP affects only the member accounts in that OU and not the other accounts in the organization. If you attach the SCP to the root OU, it will apply to all accounts in the organization, including the production account, which is not the desired outcome.If you attach the SCP to the management account, it will have no effect, as SCPs do not affect users or roles in the management account1.

Therefore, the best solutions to deploy the SCP are B and E. Option B attaches the SCP directly to the three nonproduction accounts, while option E creates a separate OU for the nonproduction accounts and attaches the SCP to the OU.Both options will achieve the same result of restricting the EC2 instance types in the nonproduction accounts, but option E might be more scalable and manageable if there are more accounts or policies to be applied in the future2.

1:Service control policies (SCPs) - AWS Organizations

2:Best Practices for AWS Organizations Service Control Policies in a Multi-Account Environment

asked 16/09/2024
Nichal Maharaj
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first