Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 367 discussion

A large payroll company recently merged with a small staffing company. The unified company now has multiple business units, each with its own existing AWS account.

A solutions architect must ensure that the company can centrally manage the billing and access policies for all the AWS accounts. The solutions architect configures AWS Organizations by sending an invitation to all member accounts of the company from a centralized management account.

What should the solutions architect do next to meet these requirements?

  • A. Create the OrganizationAccountAccess IAM group in each member account. Include the necessary IAM roles for each administrator.
  • B. Create the OrganizationAccountAccessPolicy IAM policy in each member account. Connect the member accounts to the management account by using cross-account access.
  • C. Create the OrganizationAccountAccessRole IAM role in each member account. Grant permission to the management account to assume the IAM role.
  • D. Create the OrganizationAccountAccessRole IAM role in the management account. Attach the AdministratorAccess AWS managed policy to the IAM role. Assign the IAM role to the administrators in each member account.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
heatblur
Highly Voted 1 year ago
Selected Answer: C
C is the Answer: This setup enables centralized management of member accounts from the management account. Administrators in the management account can assume the OrganizationAccountAccessRole in member accounts to perform necessary actions, aligning with AWS best practices for Organizations. It simplifies the management and auditing of various accounts and ensures a standardized role exists across all accounts for consistent access control.
upvoted 9 times
...
yuliaqwerty
Highly Voted 11 months, 1 week ago
C https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_accounts_access.html#orgs_manage_accounts_create-cross-account-role
upvoted 5 times
JMAN1
10 months, 3 weeks ago
Thank you!
upvoted 2 times
...
...
AzureDP900
Most Recent 1 week, 2 days ago
Option C is correct By creating an IAM role in each member account, you can define the specific permissions and controls for access to resources within that account. Granting permission to the management account to assume the IAM role allows administrators in one account to take control of another account, while still maintaining a centralized level of control. Option C is correct because it provides a way to: Centralize access to resources across multiple accounts Define specific permissions and controls for each account Allow administrators in one account to assume control of another account
upvoted 1 times
...
career360guru
8 months, 2 weeks ago
Selected Answer: C
Option C
upvoted 1 times
...
ftaws
10 months ago
Is it possible C ? Role in the each member account and management account just grant assume the role. How to implement it? @@
upvoted 1 times
...
ayadmawla
11 months, 3 weeks ago
Selected Answer: C
See: https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_accounts_access.html
upvoted 3 times
...
J0n102
11 months, 3 weeks ago
Selected Answer: C
Answer: C
upvoted 2 times
...
shaaam80
12 months ago
Selected Answer: C
OrganizationAccountAccessRole is created in the member accounts and this role can be assumed by IAM users in the Management account to perform any actions in member accounts. Answer C.
upvoted 3 times
...
George88
1 year ago
Answer: C https://fullbacksystems.com/aws_organizations/
upvoted 2 times
...
devalenzuela86
1 year ago
Answer D. Be is not correct To centrally manage the billing and access policies for all the AWS accounts of a company that has multiple business units, each with its own existing AWS account, the following steps can be taken: 1.Create an organization in AWS Organizations. Set up AWS Control Tower, and turn on the strongly recommended controls (guardrails). Join all accounts to the organization. Categorize the AWS accounts into OUs. 2.Create the OrganizationAccountAccessRole IAM role in the management account. Attach the AdministratorAccess AWS managed policy to the IAM role. Assign the IAM role to the administrators in each member account
upvoted 2 times
...
devalenzuela86
1 year ago
Selected Answer: B
Option B is the correct solution because it creates the OrganizationAccountAccessPolicy IAM policy in each member account and connects the member accounts to the management account by using cross-account access. This will ensure that the company can centrally manage the billing and access policies for all the AWS accounts.
upvoted 2 times
...
cypkir
1 year ago
Selected Answer: C
Answer: C
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...