exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 351 discussion

A company has a project that is launching Amazon EC2 instances that are larger than required. The project's account cannot be part of the company's organization in AWS Organizations due to policy restrictions to keep this activity outside of corporate IT. The company wants to allow only the launch of t3.small EC2 instances by developers in the project's account. These EC2 instances must be restricted to the us-east-2 Region.

What should a solutions architect do to meet these requirements?

  • A. Create a new developer account. Move all EC2 instances, users, and assets into us-east-2. Add the account to the company's organization in AWS Organizations. Enforce a tagging policy that denotes Region affinity.
  • B. Create an SCP that denies the launch of all EC2 instances except t3.small EC2 instances in us-east-2. Attach the SCP to the project's account.
  • C. Create and purchase a t3.small EC2 Reserved Instance for each developer in us-east-2. Assign each developer a specific EC2 instance with their name as the tag.
  • D. Create an IAM policy than allows the launch of only t3.small EC2 instances in us-east-2. Attach the policy to the roles and groups that the developers use in the project's account.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
George88
Highly Voted 10 months, 1 week ago
Should be D. Question says "The project's account cannot be part of the company's organization in AWS Organizations due to policy restrictions to keep this activity outside of corporate IT" You need organisation for SCP.
upvoted 14 times
...
trungtd
Most Recent 3 months, 3 weeks ago
Selected Answer: D
only possible way
upvoted 1 times
...
svenkata18
4 months, 3 weeks ago
C Why not C as developers has to select only T3.small. why can't we purchase RI with only T3.small
upvoted 1 times
...
Russs99
7 months ago
Selected Answer: D
option D is the only answer. the scenario clearly stated the IT team in this project cannot be part of the organization.
upvoted 2 times
...
career360guru
8 months, 3 weeks ago
Selected Answer: D
Option D
upvoted 1 times
...
vibzr2023
8 months, 3 weeks ago
Answer D: Option B: An SCP can manage IAM permissions across an organization, but the project account isn't part of the organization.
upvoted 1 times
...
ayadmawla
9 months, 3 weeks ago
Selected Answer: D
SCP can be applied only to those users and roles which are managed by accounts that are part of any organization See: https://digitalcloud.training/aws-scp-mastering-aws-service-control-policies/#:~:text=SCP%20can%20be%20applied%20only,including%20the%20account's%20root%20user.
upvoted 1 times
...
Russs99
9 months, 3 weeks ago
Selected Answer: D
D meets the needs with an IAM-based access control policy specific to the standalone project account and its developers' roles/groups.
upvoted 1 times
...
Maygam
10 months, 1 week ago
Selected Answer: B
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examples_ec2.html#example-ec2-1
upvoted 1 times
albert_kuo
2 weeks, 4 days ago
due to policy restrictions to keep this activity outside of corporate IT
upvoted 1 times
...
...
cypkir
10 months, 1 week ago
Selected Answer: D
Answer: D
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago