Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 43 discussion

A security engineer is using AWS Organizations and wants to optimize SCPs. The security engineer needs to ensure that the SCPs conform to best practices.
Which approach should the security engineer take to meet this requirement?

  • A. Use AWS IAM Access Analyzer to analyze the polices. View the findings from policy validation checks.
  • B. Review AWS Trusted Advisor checks for all accounts in the organization.
  • C. Set up AWS Audit Manager. Run an assessment for all AWS Regions for all accounts.
  • D. Ensure that Amazon Inspector agents are installed on all Amazon EC2 instances in all accounts.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
bannium
Highly Voted 11 months, 1 week ago
Selected Answer: A
It seems IAM Access Analyzer > This powerful new feature will help you to construct IAM policies and SCPs that take advantage of time-tested AWS best practices. https://aws.amazon.com/jp/blogs/aws/iam-access-analyzer-update-policy-validation/
upvoted 5 times
...
Raphaello
Most Recent 8 months ago
Selected Answer: A
IAM Access Analyzer.
upvoted 1 times
...
trashbox
9 months, 3 weeks ago
Exam on 2023-12-18
upvoted 1 times
...
AgboolaKun
11 months ago
Selected Answer: A
You can create AWS IAM Access Analyzer in AWS Organizations as the zone of trust. https://aws.amazon.com/blogs/aws/new-use-aws-iam-access-analyzer-in-aws-organizations/
upvoted 2 times
...
pupsik
11 months, 2 weeks ago
Selected Answer: A
I don't think Trusted Advisor would give insights regarding SCP configurations, hence A.
upvoted 1 times
...
ahrentom
11 months, 2 weeks ago
Selected Answer: B
best practices --> Trusted Advisor
upvoted 1 times
Aamee
10 months ago
No, cuz Trusted Advisor doesn't analyze anything with the SCP level so hence A is correct here.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...