exam questions

Exam AWS Certified Solutions Architect - Professional All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional exam

Exam AWS Certified Solutions Architect - Professional topic 1 question 996 discussion

A company uses AWS Organizations to manage its AWS accounts. A solutions architect must design a solution in which only administrator roles are allowed to use IAM actions. However, the solutions architect does not have access to all the AWS accounts throughout the company.

Which solution meets these requirements with the LEAST operational overhead?

  • A. Create an SCP that applies to all the AWS accounts to allow IAM actions only for administrator roles. Apply the SCP to the root OU.
  • B. Configure AWS CloudTrail to invoke an AWS Lambda function for each event that is related to IAM actions. Configure the function to deny the action if the user who invoked the action is not an administrator.
  • C. Create an SCP that applies to all the AWS accounts to deny IAM actions for all users except for those with administrator roles. Apply the SCP to the root OU.
  • D. Set an IAM permissions boundary that allows IAM actions. Attach the permissions boundary to every administrator role across all the AWS accounts.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Kende
Highly Voted 2 years, 6 months ago
Selected Answer: C
"C" is the one.
upvoted 6 times
...
Ebi
Most Recent 1 year, 4 months ago
Correct is C
upvoted 1 times
...
kaws8902
1 year, 6 months ago
I picked C, but curious why it might not be A.
upvoted 1 times
marszalekm
1 year, 5 months ago
I wonder as well, SCP deny be default, so if something is not allowed, it is denied by defualt. Or am I missing something?
upvoted 1 times
marszalekm
1 year, 5 months ago
Oh, I guess one should assume that default policy (FullAWSAccess) allowing everything is attached, then it makes sense.
upvoted 1 times
...
...
...
ggrodskiy
2 years, 6 months ago
Correct C
upvoted 4 times
ggrodskiy
2 years, 6 months ago
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...