exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 114 discussion

A company deploys a set of standard IAM roles in AWS accounts. The IAM roles are based on job functions within the company. To balance operational efficiency and security, a security engineer implemented AWS Organizations SCPs to restrict access to critical security services in all company accounts.

All of the company's accounts and OUs within AWS Organizations have a default FullAWSAccess SCP that is attached. The security engineer needs to ensure that no one can disable Amazon GuardDuty and AWS Security Hub. The security engineer also must not override other permissions that are granted by IAM policies that are defined in the accounts.

Which SCP should the security engineer attach to the root of the organization to meet these requirements?

  • A.
  • B.
  • C.
  • D.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ale_brd_111
8 months, 2 weeks ago
Selected Answer: A
gotta be A
upvoted 2 times
...
ahrentom
1 year ago
Selected Answer: A
A is correct, key word in SCP is to Deny, because it overwrites the FullAccessSCP Alow statement.
upvoted 3 times
...
AgboolaKun
1 year ago
Selected Answer: A
A is correct. The NotAction element cannot be used in this case. You only need an explicit DENY here since all accounts and OUs already have a default FullAWSAccess SCP but you don't want them to be able to disable Amazon GuardDuty and AWS Security Hub.
upvoted 3 times
Sab31
11 months, 1 week ago
Kindly correct me if I am wrong. When we attach a new SCP the default FullAWSAccess SCP is detached from the OU. isn't that right?
upvoted 1 times
...
...
Aamee
1 year ago
Selected Answer: D
Probably going with D but still not 100% sure how is it going to work that way... would appreciate if someone could help in understanding this question..
upvoted 2 times
LeoD
1 year ago
SCPs do not support NotAction with effect Allow.
upvoted 2 times
Zek
6 months, 3 weeks ago
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_syntax.html#scp-elements-table
upvoted 1 times
...
Aamee
1 year ago
Ah ok, got it...thnx so much... in this way, probably looks like all other options are invalid except option A since on all others they've used 'NotAction' attribute with Allow directly and indirectly which won't work..
upvoted 2 times
...
...
...
[Removed]
1 year ago
A. OU level will still have access to other services outside of Guardduty and Security Hub due to the OU level policy. D could work but is not necessary
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago