ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 125 - SCS-C01 discussion

Report
Export

A Security Administrator is restricting the capabilities of company root user accounts. The company uses AWS Organizations and has enabled it for all feature sets, including consolidated billing. The top-level account is used for billing and administrative purposes, not for operational AWS resource purposes.

How can the Administrator restrict usage of member root user accounts across the organization?

A.
Disable the use of the root user account at the organizational root. Enable multi-factor authentication of the root user account for each organizational member account.
Answers
A.
Disable the use of the root user account at the organizational root. Enable multi-factor authentication of the root user account for each organizational member account.
B.
Configure IAM user policies to restrict root account capabilities for each Organizations member account.
Answers
B.
Configure IAM user policies to restrict root account capabilities for each Organizations member account.
C.
Create an organizational unit (OU) in Organizations with a service control policy that controls usage of the root user. Add all operational accounts to the new OU.
Answers
C.
Create an organizational unit (OU) in Organizations with a service control policy that controls usage of the root user. Add all operational accounts to the new OU.
D.
Configure AWS CloudTrail to integrate with Amazon CloudWatch Logs and then create a metric filter for RootAccountUsage.
Answers
D.
Configure AWS CloudTrail to integrate with Amazon CloudWatch Logs and then create a metric filter for RootAccountUsage.
Suggested answer: C

Explanation:

Applying a "Control Policy" in your organization. A policy applied to: 1) root applies to all accounts in the organization 2) OU applies to all accounts in the OU and to any child OUs 3) account applies to one account only Note- this requires that Acquirements: -all features are enabled for the organization in AWS Organizations -Only service control policy (SCP) are supported https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies.html

asked 16/09/2024
pheangphadhu pravitpinyo
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first