List of questions
Related questions
Question 266 - SCS-C02 discussion
A company has an organization with SCPs in AWS Organizations. The root SCP for the organization is as follows:
The company's developers are members of a group that has an IAM policy that allows access to Amazon Simple Email Service (Amazon SES) by allowing ses:* actions. The account is a child to an OU that has an SCP that allows Amazon SES. The developers are receiving a not-authorized error when they try to access Amazon SES through the AWS Management Console.
Which change must a security engineer implement so that the developers can access Amazon SES?
A.
Add a resource policy that allows each member of the group to access Amazon SES.
B.
Add a resource policy that allows 'Principal': {'AWS': 'arn:aws:iam::account-number:group/Dev'}.
C.
Remove the AWS Control Tower control (guardrail) that restricts access to Amazon SES.
D.
Remove Amazon SES from the root SCP.
Your answer:
0 comments
Sorted by
Leave a comment first