Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 668 discussion

A company created a new organization in AWS Organizations. The organization has multiple accounts for the company's development teams. The development team members use AWS IAM Identity Center (AWS Single Sign-On) to access the accounts. For each of the company's applications, the development teams must use a predefined application name to tag resources that are created.

A solutions architect needs to design a solution that gives the development team the ability to create resources only if the application name tag has an approved value.

Which solution will meet these requirements?

  • A. Create an IAM group that has a conditional Allow policy that requires the application name tag to be specified for resources to be created.
  • B. Create a cross-account role that has a Deny policy for any resource that has the application name tag.
  • C. Create a resource group in AWS Resource Groups to validate that the tags are applied to all resources in all accounts.
  • D. Create a tag policy in Organizations that has a list of allowed application names.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
awsgeek75
Highly Voted 10 months, 1 week ago
Selected Answer: D
A: Don't think this is possible. B: Cross account role with deny policy? Never seen anything like this C: Resource groups have nothing to do with allowed tags D: Correct https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_tag-policies.html
upvoted 5 times
...
pentium75
Most Recent 10 months, 3 weeks ago
Selected Answer: D
Other options don't make sense
upvoted 3 times
...
m_y_s
11 months, 2 weeks ago
Selected Answer: D
A tag policy can also specify that noncompliant tagging operations on specified resource types are enforced. In other words, noncompliant tagging requests on specified resource types are prevented from completing.
upvoted 1 times
...
Beshowasfy
11 months, 2 weeks ago
Selected Answer: D
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_tag-policies.html
upvoted 2 times
...
SHAAHIBHUSHANAWS
11 months, 3 weeks ago
D https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_tag-policies.html
upvoted 1 times
...
rcptryk
11 months, 3 weeks ago
Selected Answer: D
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_tag-policies.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...