exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 882 discussion

Exam question from Amazon's AWS-SysOps
Question #: 882
Topic #: 1
[All AWS-SysOps Questions]

A company is managing multiple AWS accounts using AWS Organizations. One of these accounts is used only for retaining logs in an Amazon S3 bucket. The company wants to make sure that compute resources cannot be used in the account.
How can this be accomplished with the LEAST administrative effort?

  • A. Apply an IAM policy to all IAM entities in the account with a statement to explicitly deny NotAction: s3:*.
  • B. Configure AWS Config to terminate compute resources that have been created in the accounts.
  • C. Configure AWS CloudTrail to block any action where the event source is not s3:amazonaws.com.
  • D. Update the service control policy on the account to deny the unapproved services.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
random_007
5 months, 4 weeks ago
Answer D
upvoted 2 times
...
TroyMcLure
6 months, 3 weeks ago
Correct Answer: D
upvoted 2 times
...
RicardoD
7 months ago
D is the answer
upvoted 4 times
...
sig
7 months, 1 week ago
Best practice => Using SCP
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago