exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 548 discussion

A company has separate AWS accounts for its finance, data analytics, and development departments. Because of costs and security concerns, the company wants to control which services each AWS account can use.

Which solution will meet these requirements with the LEAST operational overhead?

  • A. Use AWS Systems Manager templates to control which AWS services each department can use.
  • B. Create organization units (OUs) for each department in AWS Organizations. Attach service control policies (SCPs) to the OUs.
  • C. Use AWS CloudFormation to automatically provision only the AWS services that each department can use.
  • D. Set up a list of products in AWS Service Catalog in the AWS accounts to manage and control the usage of specific AWS services.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
zdi561
1 day ago
Selected Answer: D
SCP set a guardrail (what you can not do, permission on IAM user and role), ASC provides templates services that you can only use.
upvoted 1 times
...
awsgeek75
7 months ago
Selected Answer: B
Departments = Organizational Units
upvoted 2 times
...
TariqKipkemei
8 months, 3 weeks ago
Selected Answer: B
Create organization units (OUs) for each department in AWS Organizations. Attach service control policies (SCPs) to the OUs
upvoted 2 times
...
ssa03
11 months, 1 week ago
Selected Answer: B
Correct Answer: B
upvoted 2 times
...
lemur88
11 months, 2 weeks ago
Selected Answer: B
SCPs to centralize permissioning
upvoted 2 times
...
Guru4Cloud
11 months, 3 weeks ago
Selected Answer: B
Create organization units (OUs) for each department in AWS Organizations. Attach service control policies (SCPs) to the OUs.
upvoted 2 times
...
xyb
12 months ago
Selected Answer: B
control services --> SCP
upvoted 2 times
...
Ale1973
12 months ago
Selected Answer: D
My rational: Scenary is "A company has separate AWS accounts", it is not mentioning anything about use of Organizations or needs related to centralized managment of these accounts. Then, set up a list of products in AWS Service Catalog in the AWS accounts (on each AWS account) is the best way to manage and control the usage of specific AWS services.
upvoted 1 times
pentium75
7 months, 1 week ago
"Separate AWS accounts" just says that it's multiple accounts, it does not indicate that they are NOT connected into a organization. Service Catalog alone does not restrict anything. You'd need to create a service in Service Catalog for everything you're allowing to use, then grant permissions on those services, and you'd need to remove other permissions from everyone. All of which is not mentioned in D. Just "setting up a list of products in AWS Service Catalog in the AWS accounts" will not restrict anyone from doing what he could do before.
upvoted 3 times
...
...
mrsoa
1 year ago
Selected Answer: B
BBBBBBBBB
upvoted 2 times
...
Deepakin96
1 year ago
Selected Answer: B
To control different AWS account you required AWS Organisation
upvoted 2 times
...
Bmaster
1 year ago
B is correct!!!!
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago