exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 367 discussion

A large payroll company recently merged with a small staffing company. The unified company now has multiple business units, each with its own existing AWS account.

A solutions architect must ensure that the company can centrally manage the billing and access policies for all the AWS accounts. The solutions architect configures AWS Organizations by sending an invitation to all member accounts of the company from a centralized management account.

What should the solutions architect do next to meet these requirements?

  • A. Create the OrganizationAccountAccess IAM group in each member account. Include the necessary IAM roles for each administrator.
  • B. Create the OrganizationAccountAccessPolicy IAM policy in each member account. Connect the member accounts to the management account by using cross-account access.
  • C. Create the OrganizationAccountAccessRole IAM role in each member account. Grant permission to the management account to assume the IAM role.
  • D. Create the OrganizationAccountAccessRole IAM role in the management account. Attach the AdministratorAccess AWS managed policy to the IAM role. Assign the IAM role to the administrators in each member account.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
heatblur
Highly Voted 1 year, 5 months ago
Selected Answer: C
C is the Answer: This setup enables centralized management of member accounts from the management account. Administrators in the management account can assume the OrganizationAccountAccessRole in member accounts to perform necessary actions, aligning with AWS best practices for Organizations. It simplifies the management and auditing of various accounts and ensures a standardized role exists across all accounts for consistent access control.
upvoted 11 times
...
yuliaqwerty
Highly Voted 1 year, 4 months ago
C https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_accounts_access.html#orgs_manage_accounts_create-cross-account-role
upvoted 5 times
JMAN1
1 year, 3 months ago
Thank you!
upvoted 2 times
...
...
AzureDP900
Most Recent 5 months, 2 weeks ago
Option C is correct By creating an IAM role in each member account, you can define the specific permissions and controls for access to resources within that account. Granting permission to the management account to assume the IAM role allows administrators in one account to take control of another account, while still maintaining a centralized level of control. Option C is correct because it provides a way to: Centralize access to resources across multiple accounts Define specific permissions and controls for each account Allow administrators in one account to assume control of another account
upvoted 1 times
...
career360guru
1 year, 1 month ago
Selected Answer: C
Option C
upvoted 1 times
...
ftaws
1 year, 3 months ago
Is it possible C ? Role in the each member account and management account just grant assume the role. How to implement it? @@
upvoted 1 times
...
ayadmawla
1 year, 4 months ago
Selected Answer: C
See: https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_accounts_access.html
upvoted 3 times
...
J0n102
1 year, 5 months ago
Selected Answer: C
Answer: C
upvoted 2 times
...
shaaam80
1 year, 5 months ago
Selected Answer: C
OrganizationAccountAccessRole is created in the member accounts and this role can be assumed by IAM users in the Management account to perform any actions in member accounts. Answer C.
upvoted 3 times
...
George88
1 year, 5 months ago
Answer: C https://fullbacksystems.com/aws_organizations/
upvoted 2 times
...
devalenzuela86
1 year, 5 months ago
Answer D. Be is not correct To centrally manage the billing and access policies for all the AWS accounts of a company that has multiple business units, each with its own existing AWS account, the following steps can be taken: 1.Create an organization in AWS Organizations. Set up AWS Control Tower, and turn on the strongly recommended controls (guardrails). Join all accounts to the organization. Categorize the AWS accounts into OUs. 2.Create the OrganizationAccountAccessRole IAM role in the management account. Attach the AdministratorAccess AWS managed policy to the IAM role. Assign the IAM role to the administrators in each member account
upvoted 2 times
...
devalenzuela86
1 year, 5 months ago
Selected Answer: B
Option B is the correct solution because it creates the OrganizationAccountAccessPolicy IAM policy in each member account and connects the member accounts to the management account by using cross-account access. This will ensure that the company can centrally manage the billing and access policies for all the AWS accounts.
upvoted 2 times
...
cypkir
1 year, 5 months ago
Selected Answer: C
Answer: C
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago