Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 878 discussion

A company creates dedicated AWS accounts in AWS Organizations for its business units. Recently, an important notification was sent to the root user email address of a business unit account instead of the assigned account owner. The company wants to ensure that all future notifications can be sent to different employees based on the notification categories of billing, operations, or security.

Which solution will meet these requirements MOST securely?

  • A. Configure each AWS account to use a single email address that the company manages. Ensure that all account owners can access the email account to receive notifications. Configure alternate contacts for each AWS account with corresponding distribution lists for the billing team, the security team, and the operations team for each business unit.
  • B. Configure each AWS account to use a different email distribution list for each business unit that the company manages. Configure each distribution list with administrator email addresses that can respond to alerts. Configure alternate contacts for each AWS account with corresponding distribution lists for the billing team, the security team, and the operations team for each business unit.
  • C. Configure each AWS account root user email address to be the individual company managed email address of one person from each business unit. Configure alternate contacts for each AWS account with corresponding distribution lists for the billing team, the security team, and the operations team for each business unit.
  • D. Configure each AWS account root user to use email aliases that go to a centralized mailbox. Configure alternate contacts for each account by using a single business managed email distribution list each for the billing team, the security team, and the operations team.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Linuslin
Highly Voted 4 months, 3 weeks ago
Selected Answer: D
D is correct answer. Configuring each AWS account's root user to use email aliases that go to a centralized mailbox ensures that sensitive notifications are not directly sent to individual email addresses. Instead, they are directed to a centralized mailbox, reducing the risk of unauthorized access to sensitive information. Additionally, configuring alternate contacts for each account using a single business-managed email distribution list for the billing team, the security team, and the operations team ensures that notifications are appropriately routed to the respective teams based on the categories of billing, operations, or security. This approach centralizes control and reduces the likelihood of misconfiguration or unauthorized access to sensitive notifications.
upvoted 6 times
Linuslin
4 months, 3 weeks ago
Option A doesn't provide the same level of security because it relies on a single email address managed by the company, which could be compromised, and it requires all account owners to access this email account, potentially leading to access control issues. Option B presents a similar issue as Option A, as it relies on different email distribution lists but still requires administrator email addresses that may be vulnerable to compromise. Option C also has security concerns because it associates the root user email address with individual employees, which may not be ideal for security and access control purposes. So, Option D is the most secure solution for ensuring that future notifications can be sent to different employees based on the notification categories of billing, operations, or security.
upvoted 5 times
...
...
MatAlves
Most Recent 3 weeks, 4 days ago
Selected Answer: D
Both B and D use Distribution Lists as part of the of the solution: B - "configure each DL with administrator email addresses that can respond to alerts" D - "configure alternate contacts for each account by using single business managed DL each" per team. I confess the wording isn't amazing, but between B and D, the latter is the one that properly addresses the issue involving root user email address.
upvoted 1 times
...
jadeconstancy
4 months ago
Selected Answer: D
correct answer is D
upvoted 2 times
...
sheilawu
4 months, 1 week ago
Selected Answer: A
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_accounts_update_primary_email.html
upvoted 2 times
...
d401c0d
5 months, 2 weeks ago
Selected Answer: A
Question mentions the email was sent to a business unit account instead of an account owner. Thus, A mentions all account owners to have access to email account.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...