A company uses AWS Organizations to manage its AWS accounts. The company has a root OU that has a child OU. The root OU has an SCP that allows all actions on all resources. The child OU has an SCP that allows all actions for Amazon DynamoDB and AWS Lambda, and denies all other actions.
The company has an AWS account that is named vendor-data in the child OU. A DevOps engineer has an IAM user that is attached to the Administrator Access IAM policy in the vendor-data account. The DevOps engineer attempts to launch an Amazon EC2 instance in the vendor-data account but receives an access denied error.
Which change should the DevOps engineer make to launch the EC2 instance in the vendor-data account?
ericphl
Highly Voted 11 months, 1 week agoSrikantha
3 months agocsG13
Highly Voted 1 year, 6 months agoSrikantha
Most Recent 3 months agoAbilash2605
10 months, 2 weeks agoauxwww
10 months, 3 weeks agoc3518fc
1 year, 2 months agodkp
1 year, 2 months agoWhyIronMan
1 year, 3 months agostoy123
1 year, 3 months agostoy123
1 year, 3 months agoDanShone
1 year, 3 months agothanhnv142
1 year, 4 months agostoy123
1 year, 3 months agoa54b16f
1 year, 5 months agod262e67
1 year, 6 months agoPrasannaBalaji
1 year, 6 months ago