exam questions

Exam AWS Certified Cloud Practitioner All Questions

View all questions & answers for the AWS Certified Cloud Practitioner exam

Exam AWS Certified Cloud Practitioner topic 1 question 34 discussion

Exam question from Amazon's AWS Certified Cloud Practitioner
Question #: 34
Topic #: 1
[All AWS Certified Cloud Practitioner Questions]

A global media company uses AWS Organizations to manage multiple AWS accounts.
Which AWS service or feature can the company use to limit the access to AWS services for member accounts?

  • A. AWS Identity and Access Management (IAM)
  • B. Service control policies (SCPs)
  • C. Organizational units (OUs)
  • D. Access control lists (ACLs)
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Prates_BR
Highly Voted 2 years, 7 months ago
A, come on admin, check this questions again!
upvoted 48 times
Guru4Cloud
2 years ago
Prates_BR - Should do more reading he correct answer is B. Service control policies (SCPs). AWS Organizations helps to manage multiple AWS accounts in a centralized manner. SCPs are a feature of AWS Organizations that allow an organization to set rules that govern the use of AWS services across all accounts in the organization. SCPs can be used to restrict the use of specific AWS services or to impose additional conditions or requirements on the use of those services. SCPs are applied at the organizational unit (OU) level, so organizations can create different policies for different groups of accounts within their AWS Organization. AWS Identity and Access Management (IAM) is a service that enables you to manage access to AWS services and resources securely. IAM is used to create and manage users, groups, and permissions. It can be used in conjunction with SCPs to further restrict access to AWS services
upvoted 20 times
...
sophire
2 years, 3 months ago
It is limiting services to member accounts from AWS Organizations. SCP is used for limiting access for any number of member accounts. Answer is B
upvoted 8 times
...
pedrolaez
1 year, 9 months ago
SCPs are the best choice for this situation as they allow control over access to multiple AWS accounts within an AWS organization, while IAM is used to manage access to a single AWS account.
upvoted 7 times
...
...
Shaychay
Highly Voted 2 years, 6 months ago
Selected Answer: B
n AWS Organizations, you can centrally control permissions for the accounts in your organization by using service control policies (SCPs). SCPs enable you to place restrictions on the AWS services, resources, and individual API actions that users and roles in each account can access.
upvoted 31 times
...
HebaXX
Most Recent 1 month ago
Selected Answer: B
Key Exam Tip: ✔ SCPs = Restrict AWS service access across accounts in AWS Organizations ✔ IAM = Manage permissions within a single AWS account ✔ OUs = Organize accounts but do not enforce policies
upvoted 1 times
...
sonaljain
4 months ago
Selected Answer: B
Service control policies (SCPs)
upvoted 1 times
...
Kaal97
4 months ago
Selected Answer: B
Service Control Policies (SCPs) within AWS Organizations to limit access to AWS services for member accounts
upvoted 1 times
...
nileshcn
1 year ago
I think answer is A
upvoted 1 times
...
indubala21
1 year, 1 month ago
i think answer could be B
upvoted 1 times
...
DrMatthew
1 year, 3 months ago
Selected Answer: B
https://www.youtube.com/watch?v=EWpj-ld1g0g
upvoted 1 times
...
rsrjunior
1 year, 4 months ago
Selected Answer: B
B - SCPs One of the features from AWS Organizations is SCPs, which helps you specify the maximum permissions for member accounts in the organization. Using SCPs, you can restrict which AWS services, resources, and individual API actions the users and roles in each member account can access. source: https://aws.amazon.com/blogs/industries/best-practices-for-aws-organizations-service-control-policies-in-a-multi-account-environment/
upvoted 1 times
...
techandra
1 year, 5 months ago
Selected Answer: B
SCP - Service Control Policies
upvoted 1 times
...
cryptics
1 year, 6 months ago
Selected Answer: B
Key Word: Limit SCPs --> Define maximum available permissions: that is where the limit comes in.
upvoted 1 times
...
grao
1 year, 7 months ago
SCPs affect only member accounts in the organization. They have no effect on users or roles in the management account.
upvoted 1 times
...
danielolasupo02
1 year, 8 months ago
Organization units ==> AWS Accounts management Service Control Policies ==> AWS Services management
upvoted 2 times
...
LabStation
1 year, 8 months ago
Selected Answer: B
B. Service Control Policies (SCPs) An organization can use Service Control Policies (SCPs) in AWS Organizations to limit access to specific AWS services to member accounts. SCPs allow an administrator to restrict service-level permissions for accounts within the organization, setting limits on which services can be accessed. The other options are not directly used to limit access to AWS services for member accounts in an AWS Organizations context: A. AWS Identity and Access Management (IAM): IAM is used to manage permissions and access within individual accounts, but does not control access to services in member accounts across AWS Organizations. C. Organizational Units (OUs): OUs are used to organize and rank accounts within the structure of AWS Organizations, but are not used to limit access to specific services. D. Access Control Lists (ACLs): ACLs generally refer to network or operating system level access control mechanisms, but are not the primary approach to controlling access to AWS services in an AWS Organizations setting .
upvoted 1 times
LabStation
1 year, 8 months ago
Continue....> D. Access Control Lists (ACLs): ACLs generally refer to network or operating system level access control mechanisms, but are not the primary approach to controlling access to AWS services in an AWS Organizations setting .
upvoted 1 times
...
...
roberto_rrt
1 year, 8 months ago
Selected Answer: A
A. AWS Identity and Access Management (IAM)
upvoted 1 times
...
Pranava_GCP
1 year, 8 months ago
Selected Answer: B
B. Service control policies (SCPs) "In SCPs, you can restrict which AWS services, resources, and individual API actions the users and roles in each member account can access. You can also define conditions for when to restrict access to AWS services, resources, and API actions. These restrictions even override the administrators of member accounts in the organization." https://docs.aws.amazon.com/organizations/latest/userguide/orgs_introduction.html#:~:text=.%20In%20SCPs%2C%20you,in%20the%20organization.
upvoted 1 times
...
saurabhfsinha
1 year, 8 months ago
Option C: organizational units (OUs): are used to group accounts together to administer as a single unit. This greatly simplifies the management of your accounts.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago