ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 91 - SCS-C02 discussion

Report
Export

A company wants to ensure that its IAM resources can be launched only in the us-east-1 and us-west-2 Regions.

What is the MOST operationally efficient solution that will prevent developers from launching Amazon EC2 instances in other Regions?

A.
Enable Amazon GuardDuty in all Regions. Create alerts to detect unauthorized activity outside us-east-1 and us-west-2.
Answers
A.
Enable Amazon GuardDuty in all Regions. Create alerts to detect unauthorized activity outside us-east-1 and us-west-2.
B.
Use an organization in IAM Organizations. Attach an SCP that allows all actions when the IAM: Requested Region condition key is either us-east-1 or us-west-2. Delete the FullIAMAccess policy.
Answers
B.
Use an organization in IAM Organizations. Attach an SCP that allows all actions when the IAM: Requested Region condition key is either us-east-1 or us-west-2. Delete the FullIAMAccess policy.
C.
Provision EC2 resources by using IAM Cloud Formation templates through IAM CodePipeline. Allow only the values of us-east-1 and us-west-2 in the IAM CloudFormation template's parameters.
Answers
C.
Provision EC2 resources by using IAM Cloud Formation templates through IAM CodePipeline. Allow only the values of us-east-1 and us-west-2 in the IAM CloudFormation template's parameters.
D.
Create an IAM Config rule to prevent unauthorized activity outside us-east-1 and us-west-2.
Answers
D.
Create an IAM Config rule to prevent unauthorized activity outside us-east-1 and us-west-2.
Suggested answer: C
asked 16/09/2024
Michael Golo
22 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first