ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 562 - SAP-C01 discussion

Report
Export

A company has implemented AWS Organizations. It has recently set up a number of new accounts and wants to deny access to a specific set of AWS services in these new accounts. How can this be controlled MOST efficiently?

A.
Create an IAM policy in each account that denies access to the services. Associate the policy with an IAM group, and add all IAM users to the group.
Answers
A.
Create an IAM policy in each account that denies access to the services. Associate the policy with an IAM group, and add all IAM users to the group.
B.
Create a service control policy that denies access to the services. Add all of the new accounts to a single organizational unit (OU), and apply the policy to that OU.
Answers
B.
Create a service control policy that denies access to the services. Add all of the new accounts to a single organizational unit (OU), and apply the policy to that OU.
C.
Create an IAM policy in each account that denies access to the services. Associate the policy with an IAM role, and instruct users to log in using their corporate credentials and assume the IAM role.
Answers
C.
Create an IAM policy in each account that denies access to the services. Associate the policy with an IAM role, and instruct users to log in using their corporate credentials and assume the IAM role.
D.
Create a service control policy that denies access to the services, and apply the policy to the root of the organization.
Answers
D.
Create a service control policy that denies access to the services, and apply the policy to the root of the organization.
Suggested answer: B

Explanation:

Reference: https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scp.html

asked 16/09/2024
Patrick Evelinton de Souza Borges
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first