exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 236 discussion

A company is designing an AWS Organizations structure. The company wants to standardize a process to apply tags across the entire organization. The company will require tags with specific values when a user creates a new resource. Each of the company's OUs will have unique tag values.

Which solution will meet these requirements?

  • A. Use an SCP to deny the creation of resources that do not have the required tags. Create a tag policy that includes the tag values that the company has assigned to each OU. Attach the tag policies to the OUs.
  • B. Use an SCP to deny the creation of resources that do not have the required tags. Create a tag policy that includes the tag values that the company has assigned to each OU. Attach the tag policies to the organization's management account.
  • C. Use an SCP to allow the creation of resources only when the resources have the required tags. Create a tag policy that includes the tag values that the company has assigned to each OU. Attach the tag policies to the OUs.
  • D. Use an SCP to deny the creation of resources that do not have the required tags. Define the list of tags. Attach the SCP to the OUs.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
duriselvan
Highly Voted 10 months, 3 weeks ago
The most suitable solution for applying standardized tags across the organization with specific values for each OU is A. Use an SCP to deny the creation of resources that do not have the required tags. Create a tag policy that includes the tag values for each OU. Attach the tag policies to the OUs. Here's why: Enforce tag standardization: An SCP applied to the entire organization denies resource creation unless the required tags are present, ensuring consistent tagging across all accounts. OU-specific tags: Tag policies attached to each OU define the specific tag values for that OU, allowing customization without compromising overall standardization. Granular control: Attaching tag policies to OUs instead of the management account provides more granular control and flexibility for managing tags within each OU.
upvoted 8 times
...
Maria2023
Highly Voted 1 year, 4 months ago
Selected Answer: A
You go to the management account -> Organizations console -> Policies -> Tag policies -> "name of the policy" -> attach to OU. That's it - A is correct
upvoted 6 times
...
duriselvan
Most Recent 10 months, 3 weeks ago
A is ans
upvoted 1 times
...
career360guru
11 months, 1 week ago
Selected Answer: A
Option A
upvoted 1 times
...
nicecurls
1 year, 3 months ago
Selected Answer: A
FOR EACH OU's
upvoted 2 times
...
NikkyDicky
1 year, 3 months ago
Selected Answer: A
it's an A
upvoted 1 times
...
dkx
1 year, 3 months ago
The correct answer is B. Imagine if you had an AWS Organization with 50+ OUs, it would be very inefficient to manually apply a generic tagging policy to each OU, so that's why there is the concept of policy inheritance: when you attach a policy to the organization root, all OUs and accounts in the organization inherit that policy When you attach a tag policy to your organization root, the tag policy applies to all of that root's member OUs and accounts. https://docs.aws.amazon.com/organizations/latest/userguide/attach-tag-policy.html Understanding policy inheritance: https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_inheritance.html
upvoted 1 times
santi1975
1 year, 3 months ago
The question clearly says "Each of the company's OUs will have unique tag values", you cannot inherit what is different. The answer is B
upvoted 4 times
santi1975
1 year, 3 months ago
Sorry, I mean cannot be B, and the correct answer is A!
upvoted 2 times
...
...
43c89f4
5 months, 4 weeks ago
The Question mentions "Each of the company's OUs will have unique tag values." the values list will change for OU's My answer is A
upvoted 2 times
...
...
Piccaso
1 year, 3 months ago
Selected Answer: A
C and D must be wrong, because of "allow ... " B is weird.
upvoted 1 times
...
SkyZeroZx
1 year, 3 months ago
Selected Answer: A
Each of the company's OUs will have unique tag values. Then A because each OU unique tags A is the unique with approved this case
upvoted 1 times
...
SmileyCloud
1 year, 4 months ago
Selected Answer: A
It's A. The policies are different for each account, so you can't assign it to the management account. Exact same scenario: https://aws.amazon.com/blogs/mt/implement-aws-resource-tagging-strategy-using-aws-tag-policies-and-service-control-policies-scps/
upvoted 3 times
...
bhanus
1 year, 4 months ago
Selected Answer: A
MODERATOR - Please remove my previous comment. From the discussion it looks like A is the answer. Looks like the tag policies should be attached at the OU level to ensure that each OU has its own unique tag values.
upvoted 1 times
...
PhuocT
1 year, 4 months ago
I think it's A
upvoted 2 times
...
gd1
1 year, 4 months ago
GPT 4. 0 says A - I agree. Values per OU
upvoted 2 times
...
easytoo
1 year, 4 months ago
b-b-b-b-b-b
upvoted 1 times
...
MoussaNoussa
1 year, 4 months ago
option A is the right answer, we need a have a list of allowed tag values per OU
upvoted 1 times
...
bhanus
1 year, 4 months ago
Selected Answer: B
B - you don't have apply SCPs to each account or OU. Attaching the tag policies to the organization's management account ensures that the policies are applied consistently to all OUs within the organization. C is incorrect because SCP are NOT used for ALLOW action. They are used for DENY actions (setting boundaries)
upvoted 3 times
bhanus
1 year, 3 months ago
changing my vote to A. The policies are different for each account, so you can't assign it to the management account.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago