Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 379 discussion

A large company is migrating its entire IT portfolio to AWS. Each business unit in the company has a standalone AWS account that supports both development and test environments. New accounts to support production workloads will be needed soon.

The finance department requires a centralized method for payment but must maintain visibility into each group's spending to allocate costs.

The security team requires a centralized mechanism to control IAM usage in all the company’s accounts.

What combination of the following options meets the company’s needs with the LEAST effort? (Choose two.)

  • A. Use a collection of parameterized AWS CloudFormation templates defining common IAM permissions that are launched into each account. Require all new and existing accounts to launch the appropriate stacks to enforce the least privilege model.
  • B. Use AWS Organizations to create a new organization from a chosen payer account and define an organizational unit hierarchy. Invite the existing accounts to join the organization and create new accounts using Organizations.
  • C. Require each business unit to use its own AWS accounts. Tag each AWS account appropriately and enable Cost Explorer to administer chargebacks.
  • D. Enable all features of AWS Organizations and establish appropriate service control policies that filter IAM permissions for sub-accounts.
  • E. Consolidate all of the company's AWS accounts into a single AWS account. Use tags for billing purposes and the IAM’s Access Advisor feature to enforce the least privilege model.
Show Suggested Answer Hide Answer
Suggested Answer: BD 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
AzureDP900
1 week, 2 days ago
B and D correct Option B: Using AWS Organizations to create a new organization from a chosen payer account and defining an organizational unit hierarchy invites existing accounts to join the organization. This allows for centralized management of IAM usage across all accounts, meeting the security team's requirement. Additionally, this approach enables cost allocation and visibility into spending for each group, which meets the finance department's requirement. Option D: Enabling all features of AWS Organizations and establishing service control policies that filter IAM permissions for sub-accounts provides a comprehensive solution for centralized IAM control. This approach allows for fine-grained control over access and security across all accounts.
upvoted 2 times
...
TonytheTiger
7 months ago
Selected Answer: BD
Option BD not C: The management account has the responsibilities of a payer account and is responsible for paying all charges that are accrued by the member accounts. You can't change an organization's management account. https://docs.aws.amazon.com/organizations/latest/userguide/orgs_getting-started_concepts.html
upvoted 2 times
...
TonytheTiger
8 months ago
Selected Answer: BD
Option BD - You need to use Service Control Policies (SCP) for the Security Team requirements. https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html
upvoted 3 times
...
a54b16f
8 months, 4 weeks ago
Selected Answer: BD
C is wrong: since it didn't mention Organization at all. We can get each group's cost by utilizing OU.
upvoted 2 times
...
Russs99
8 months, 4 weeks ago
Selected Answer: BC
options B and C offers a balance between centralized management, cost visibility, and minimal disruption during the migration process. The company can leverage AWS Organizations to establish a central structure and implement security controls later, while maintaining separate accounts for business units with tagging and Cost Explorer to ensure cost allocation. i maybe wrong, but these are my picks
upvoted 4 times
anubha.agrahari
5 months, 3 weeks ago
Agreed
upvoted 1 times
...
...
alexandercamachop
9 months ago
Selected Answer: BC
BC We need AWS Organization and we need tagging for cost allocation. Those are the only answers viable.
upvoted 1 times
...
bjexamprep
9 months ago
Selected Answer: BC
“Centralized method for payment” maps to AWS organization. So B is one of the answer. “maintain visibility into each group's spending to allocate costs” means all resources need to be tagged for Cost Explorer to provide visibility into each group’s spending. So, C is one of the answer I don’t think D is a good answer, coz SCP is not a good way for IAM permission control. The usual way is to create different roles and allow different users/groups to assume different roles. A is wrong because there isn’t so called common IAM permissions; and least privilege model is a best practice rather than a detailed template, so there is nothing to enforce. E Consolidating accounts into one single account is obviously not a good solution.
upvoted 2 times
...
rajkanch
10 months, 1 week ago
Why not B,C? It looks good to me.
upvoted 2 times
...
career360guru
10 months, 2 weeks ago
Selected Answer: BD
Option B and D
upvoted 1 times
...
yuliaqwerty
11 months, 1 week ago
Also vote for B and D
upvoted 1 times
...
shaaam80
12 months ago
B & D - Create Organizations in AWS Organizations from a chosen payer account and invite all member accounts and create new accounts as a part of the Organizations. Enable All features and create appropriate SCPs for services access control.
upvoted 2 times
...
thala
1 year ago
Selected Answer: BD
Options B and D offers a centralized, efficient, and scalable solution that meets both the finance department's and the security team's requirements.
upvoted 4 times
...
devalenzuela86
1 year ago
Selected Answer: BD
BD for sure
upvoted 2 times
...
cypkir
1 year ago
Selected Answer: BD
Answer: B D
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...