List of questions
Related questions
Question 504 - SCS-C01 discussion
A company wants to ensure that its AWS resources can be launched only in the us-east-1 and uswest- 2 Regions. What is the MOST operationally efficient solution that will prevent developers from launching Amazon EC2 instances in other Regions?
A.
Enable Amazon GuardDuty in all Regions. Create alerts to detect unauthorized activity outside useast- 1 and us-west-2.
B.
Use an organization in AWS Organizations. Attach an SCP that allows all actions when the aws:Requested Region condition key is either us-east-1 or us-west-2. Delete the FullAWSAccess policy.
C.
Provision EC2 resources by using AWS Cloud Formation templates through AWS CodePipeline.Allow only the values of us-east-1 and us-west-2 in the AWS CloudFormation template's parameters.
D.
Create an AWS Config rule to prevent unauthorized activity outside us-east-1 and us-west-2.
Your answer:
0 comments
Sorted by
Leave a comment first