ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 365 - SOA-C02 discussion

Report
Export

A company wants to prohibit its developers from using a particular family of Amazon EC2 instances The company uses AWS Organizations and wants to apply the restriction across multiple accounts

What is the MOST operationally efficient way for the company lo apply service control policies (SCPs) to meet these requirements?

A.
Add the accounts to an organizational unit (OUf Apply the SCPs to the OU.
Answers
A.
Add the accounts to an organizational unit (OUf Apply the SCPs to the OU.
B.
Add the accounts to resource groups in AWS Resource Groups. Apply the SCPs to the resource groups.
Answers
B.
Add the accounts to resource groups in AWS Resource Groups. Apply the SCPs to the resource groups.
C.
Apply the SCPs to each developer account.
Answers
C.
Apply the SCPs to each developer account.
D.
Enroll the accounts with AWS Control Tower. Apply the SCPs to the AWS Control Tower management account.
Answers
D.
Enroll the accounts with AWS Control Tower. Apply the SCPs to the AWS Control Tower management account.
Suggested answer: A

Explanation:

Applying SCPs to an Organizational Unit:

Service Control Policies (SCPs) allow you to manage permissions for multiple AWS accounts within an organization.

Steps:

Go to the AWS Management Console.

Navigate to AWS Organizations.

Create an Organizational Unit (OU) if not already created.

Move the target accounts into the OU.

Create an SCP that denies the use of the specific EC2 instance family.

Attach the SCP to the OU.

This approach ensures that the policy is applied consistently across all accounts in the OU.

asked 16/09/2024
Alex Rector
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first