exam questions

Exam AWS Certified Cloud Practitioner All Questions

View all questions & answers for the AWS Certified Cloud Practitioner exam

Exam AWS Certified Cloud Practitioner topic 1 question 773 discussion

Exam question from Amazon's AWS Certified Cloud Practitioner
Question #: 773
Topic #: 1
[All AWS Certified Cloud Practitioner Questions]

A company wants to implement controls (guardrails) in a newly created AWS Control Tower landing zone.

Which AWS services or features can the company use to create and define these controls (guardrails)? (Choose two.)

  • A. AWS Config
  • B. Service control policies (SCPs)
  • C. Amazon Guard Duly
  • D. AWS Identity and Access Management (1AM)
  • E. Security groups
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
oskarq
Highly Voted 1 year, 9 months ago
Selected Answer: AB
Implementation of control behavior The preventive controls are implemented using Service Control Policies (SCPs), which are part of AWS Organizations. The detective controls are implemented using AWS Config rules. The proactive controls are implemented using AWS CloudFormation hooks.
upvoted 5 times
...
Santosh4u
Most Recent 4 months, 2 weeks ago
Selected Answer: AB
AWS Config is used to assess, audit, and evaluate the configurations of AWS resources, ensuring compliance with desired configurations. Service control policies (SCPs) helps to enforce preventive guardrails by specifying the maximum permissions for accounts in an organization, ensuring users cannot perform unauthorized actions.
upvoted 1 times
...
Pranava_GCP
1 year, 9 months ago
Selected Answer: BD
B. Service control policies (SCPs) D. AWS Identity and Access Management (IAM)
upvoted 2 times
...
[Removed]
1 year, 10 months ago
Selected Answer: AB
For those who are familiar with AWS: In AWS Control Tower preventive controls are implemented with Service Control Policies (SCPs). Detective controls are implemented with AWS Config rules. Proactive controls are implemented with AWS CloudFormation hooks. Referance:https://docs.aws.amazon.com/controltower/latest/userguide/how-control-tower-works.html#how-controls-work
upvoted 2 times
...
beastdabest
1 year, 10 months ago
Selected Answer: BD
B. Service control policies D. AWS Identity and Access Management (IAM)
upvoted 2 times
...
Zonci
1 year, 10 months ago
Selected Answer: BD
B. Service control policies (SCPs): Service control policies are used to define fine-grained permissions for AWS accounts within an organization. With SCPs, you can establish guardrails by setting restrictions on the actions that IAM entities (users, groups, roles) can perform on AWS services and resources. D. AWS Identity and Access Management (IAM): IAM is a service that enables you to manage user access and permissions to AWS services and resources. Within an AWS Control Tower landing zone, you can use IAM to create and manage IAM roles, policies, and permissions.
upvoted 1 times
...
AngloSoliman
1 year, 11 months ago
Selected Answer: AB
The correct answers are (SCPs and AWS Config). For those who are familiar with AWS: In AWS Control Tower preventive controls are implemented with Service Control Policies (SCPs). Detective controls are implemented with AWS Config rules. Proactive controls are implemented with AWS CloudFormation hooks. Ref:https://docs.aws.amazon.com/controltower/latest/userguide/how-control-tower-works.html#how-controls-work
upvoted 2 times
...
Guru4Cloud
2 years ago
Selected Answer: BD
When creating a new AWS Control Tower landing zone, you can define policies to enforce permissions boundaries and ensure compliance across your AWS environment. AWS provides several services and features to help create and define these policies, and two of the primary tools are Service Control Policies (SCPs) and AWS Identity and Access Management (IAM) policies. Service Control Policies (SCPs) are used to define permission guardrails across accounts in a Control Tower landing zone. With SCPs, you can limit permissions for IAM entities (users, groups, and roles) and the resources they can access. SCPs work as a whitelist, explicitly allowing access to only the specified resources and services, and denying access to all other resources and services. This helps to enforce compliance policies across all accounts and resources within the AWS Control Tower environment.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago