exam questions

Exam AWS Certified Solutions Architect - Professional SAP-C02 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Professional SAP-C02 exam

Exam AWS Certified Solutions Architect - Professional SAP-C02 topic 1 question 464 discussion

A company uses AWS Organizations to manage its AWS accounts. A solutions architect must design a solution in which only administrator roles are allowed to use IAM actions. However, the solutions architect does not have access to all the AWS accounts throughout the company.

Which solution meets these requirements with the LEAST operational overhead?

  • A. Create an SCP that applies to all the AWS accounts to allow IAM actions only for administrator roles. Apply the SCP to the root OU.
  • B. Configure AWS CloudTrail to invoke an AWS Lambda function for each event that is related to IAM actions. Configure the function to deny the action if the user who invoked the action is not an administrator.
  • C. Create an SCP that applies to all the AWS accounts to deny IAM actions for all users except for those with administrator roles. Apply the SCP to the root OU.
  • D. Set an IAM permissions boundary that allows IAM actions. Attach the permissions boundary to every administrator role across all the AWS accounts.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Dgix
Highly Voted 8 months, 3 weeks ago
Selected Answer: C
A: SCPs don't allow, they deny B: is reactive, not preventive C: is correct D: Boundary Permissions don't allow, they set maximum permissions.
upvoted 5 times
...
Spike2020
Most Recent 2 days, 1 hour ago
Selected Answer: C
I will go with C. But between A & C it is very confusing. You can understand the question that SCP deny actions by default and hence you need to allow actions, or if you are white listing you need to deny actions explicitly.
upvoted 1 times
...
AzureDP900
1 month ago
Option C involves creating an SCP that denies IAM actions for all users except those with administrator roles. This approach ensures that only administrators can perform IAM actions, meeting one of the key requirements. The use of an SCP to deny permissions also provides a more centralized and scalable solution compared to options A or D, which focus on allowing specific permissions for administrators. Applying this SCP to the root OU will ensure it applies to all child OUs and their respective AWS accounts, meeting the requirement of enforcing the policy across multiple accounts.
upvoted 1 times
...
ff32d79
4 months ago
If an SCP allows certain IAM actions specifically for administrator roles or groups, it implicitly denies those actions for all other roles and users in the accounts where the SCP is applied. You do not need to explicitly deny the actions for non-administrator roles and users. The implicit deny happens automatically because SCPs define the maximum permissible permissions. So it is A. With C at every new role you have to define it. And Administrators by default have in their IAM permission the capacity to do the modifications.
upvoted 2 times
dv1
1 week, 3 days ago
By default, AWS Org has the SCP "FullAWSAccess" that allows access to every operation. If you explicitly allow IAM actions for administrators without deleting this policy (not mentioned in the answer), you have done nothing. So C is best approach.
upvoted 1 times
...
...
pangchn
8 months, 3 weeks ago
Selected Answer: C
C using SCP deny
upvoted 3 times
...
CMMC
8 months, 4 weeks ago
Selected Answer: C
Applying SCP to the root OU with specified deny rule
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago