exam questions

Exam AWS-SysOps All Questions

View all questions & answers for the AWS-SysOps exam

Exam AWS-SysOps topic 1 question 648 discussion

Exam question from Amazon's AWS-SysOps
Question #: 648
Topic #: 1
[All AWS-SysOps Questions]

A company wants to ensure that each department operates within their own isolated environment, and they are only able to use pre-approved services.
How can this requirement be met?

  • A. Set up an AWS Organization to create accounts for each department, and apply service control policies to control access to AWS services.
  • B. Create IAM roles for each department, and set policies that grant access to specific AWS services.
  • C. Use the AWS Service Catalog to create catalogs of AWS services that are approved for use by each department.
  • D. Request that each department create and manage its own AWS account and the resources within it.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
grekh001
Highly Voted 2 years, 6 months ago
This question has 2 requirements. 1. Isolated Environments 2. Pre-Approved Services Many comments seem to only be focusing only on the second requirement and are suggesting Service Catalogs. But that will not satisfy the first requirement of Isolated Environments. The correct answer is A which satisfies both requirements.
upvoted 21 times
sapien45
2 years, 5 months ago
good catch
upvoted 1 times
...
...
cloud
Highly Voted 2 years, 6 months ago
"C" AWS Service Catalog provides a single location where organizations can centrally manage catalogs of IT services. With AWS Service Catalog you can control which IT services and versions are available, the configuration of the available services, and permission access by individual, group, department, or cost center.
upvoted 12 times
Kimle
2 years, 6 months ago
A . as it provides both isolated environment "which service catalog don't" and preapproved services "via SCP"
upvoted 2 times
...
...
albert_kuo
Most Recent 9 months, 3 weeks ago
Selected Answer: A
Service control policies (SCPs) can be applied at the organization, account, or organizational unit (OU) level within AWS Organizations. SCPs define the permissions and services that are allowed or denied for specific accounts or OUs. By applying SCPs, you can restrict each department's access to only the pre-approved services that are necessary for their operations.
upvoted 1 times
albert_kuo
6 months, 1 week ago
Change to C
upvoted 1 times
...
...
alexsandroe
2 years, 5 months ago
A. Set up an AWS Organization to create accounts for each department, and apply service control policies to control access to AWS services.
upvoted 2 times
...
yolohibee
2 years, 5 months ago
Answer is C. See https://aws.amazon.com/es/blogs/mt/standardizing-infrastructure-delivery-in-distributed-environments-using-aws-service-catalog/
upvoted 1 times
...
RicardoD
2 years, 5 months ago
C is the answer AWS Service Catalog administrators can reference an existing organization in AWS Organizations when sharing a portfolio, and they can share the portfolio with any trusted organizational unit (OU) in the organization's tree structure
upvoted 1 times
...
abhishek_m_86
2 years, 6 months ago
A. Set up an AWS Organization to create accounts for each department, and apply service control policies to control access to AWS services.
upvoted 4 times
...
Jordanro
2 years, 6 months ago
I'll go with A Isolation -> Separate accounts Pre-approved services -> Service Control Policies (SCP)
upvoted 4 times
...
kiev
2 years, 6 months ago
The key word here is pre approved and in aws organisation you can you service control policy to limit what any departments can do and so A is the answer.
upvoted 3 times
...
jackdryan
2 years, 6 months ago
I'll go with A
upvoted 4 times
...
MFDOOM
2 years, 6 months ago
C. use the AWS Service Catalog to create catalogs of AWS services that are approved for use by each department.
upvoted 2 times
...
Polu
2 years, 6 months ago
A - With service catalogue you cannot use the AWS service completely ie. a user cannot modify a LAMP stack (for example) created by a servie catalogue , canot change instacnce type , EBS etc etc.
upvoted 2 times
...
waterzhong
2 years, 6 months ago
C. Service Catalog.
upvoted 1 times
...
MrDEVOPS
2 years, 6 months ago
ANS C:- Pre-approved services features Isolation too :- [AWS Service Catalog provides the following benefits: ... separated and isolated Availability Zones, which are connected with low-latency,. ] Why not A :- no "pre approved services".
upvoted 1 times
...
KhatriRocks
2 years, 6 months ago
pre-approved services, C
upvoted 1 times
...
JGD
2 years, 6 months ago
Answer A: Using AWS organization, we can isolate the environment, which means one user cannot see other user's resources. To limit the services, we can use Service Control.
upvoted 5 times
...
SHoKMaSTeR
2 years, 6 months ago
C. Service Catalog. Check the diagram of this doc: https://aws.amazon.com/es/blogs/mt/standardizing-infrastructure-delivery-in-distributed-environments-using-aws-service-catalog/
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago