exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 334 discussion

A company has multiple AWS accounts. The company uses AWS Organizations with an organizational unit (OU) for the production account and another OU for the development account. Corporate policies state that developers may use only approved AWS services in the production account.

What is the MOST operationally efficient solution to control the production account?

  • A. Create a customer managed policy in AWS Identity and Access Management (IAM). Apply the policy to all users within the production account.
  • B. Create a job function policy in AWS Identity and Access Management (IAM). Apply the policy to all users within the production OU.
  • C. Create a service control policy (SCP). Apply the SCP to the production OU.
  • D. Create an IAM policy. Apply the policy in Amazon API Gateway to restrict the production account.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
tgv
6 months, 2 weeks ago
Selected Answer: C
SCP to control the permissions of the developers in the production account.
upvoted 1 times
...
mh8
1 year, 3 months ago
Selected Answer: C
I would go with C as per the previous questions.
upvoted 2 times
...
[Removed]
1 year, 3 months ago
To control the use of approved AWS services in the production account, the most operationally efficient solution would be to create a service control policy (SCP) and apply it to the production organizational unit (OU). An SCP is a type of policy that you can use with AWS Organizations to manage permissions in your organization’s accounts. With an SCP, you can specify the services and actions that users and roles can use in the accounts that are part of the OU to which the SCP is attached. This allows you to centrally control the use of approved AWS services in the production account. So, the correct answer would be C. Create a service control policy (SCP). Apply the SCP to the production OU.
upvoted 4 times
...
Pete987
1 year, 3 months ago
Selected Answer: C
C: SCP
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago