exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 228 discussion

A security administrator is restricting the capabilities of company root user accounts. The company uses AWS Organizations and has all features enabled.
The management account is used for billing and administrative purposes, but it is not used for operational AWS resource purposes.

How can the security administrator restrict usage of member root user accounts across the organization?

  • A. Disable the use of the root user account at the organizational root. Enable multi-factor authentication (MFA) of the root user account for each organization member account.
  • B. Configure IAM user policies to restrict root account capabilities for each organization member account.
  • C. Create an OU in Organizations, and attach an SCP that controls usage of the root user. Add all member accounts to the new OU.
  • D. Configure AWS CloudTrail to integrate with Amazon CloudWatch Logs. Create a metric filter for RootAccountUsage.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
molerowan
2 days, 20 hours ago
Selected Answer: C
SCP Enforcement: SCPs act as guardrails, preventing root users in member accounts from performing any AWS actions. Centralized Management: The SCP is managed by the organization’s management account, ensuring member root users cannot bypass it.
upvoted 1 times
...
Pmktechno
2 months, 2 weeks ago
Selected Answer: C
his approach allows you to centrally manage and enforce restrictions on root user accounts across all member accounts in the organization by using Service Control Policies (SCPs). This ensures that the root user capabilities are consistently controlled and limited according to the organization's security policies.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago