Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 151 discussion

A company wants to migrate its on-premises data center to AWS. According to the company's compliance requirements, the company can use only the ap-northeast-3 Region. Company administrators are not permitted to connect VPCs to the internet.
Which solutions will meet these requirements? (Choose two.)

  • A. Use AWS Control Tower to implement data residency guardrails to deny internet access and deny access to all AWS Regions except ap-northeast-3.
  • B. Use rules in AWS WAF to prevent internet access. Deny access to all AWS Regions except ap-northeast-3 in the AWS account settings.
  • C. Use AWS Organizations to configure service control policies (SCPS) that prevent VPCs from gaining internet access. Deny access to all AWS Regions except ap-northeast-3.
  • D. Create an outbound rule for the network ACL in each VPC to deny all traffic from 0.0.0.0/0. Create an IAM policy for each user to prevent the use of any AWS Region other than ap-northeast-3.
  • E. Use AWS Config to activate managed rules to detect and alert for internet gateways and to detect and alert for new resources deployed outside of ap-northeast-3.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Six_Fingered_Jose
Highly Voted 1 year, 8 months ago
Selected Answer: AC
agree with A and C https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examples_vpc.html#example_vpc_2
upvoted 19 times
...
cookieMr
Highly Voted 1 year ago
Selected Answer: AC
A. By using Control Tower, the company can enforce data residency guardrails and restrict internet access for VPCs and denies access to all Regions except the required ap-northeast-3 Region. C. With Organizations, the company can configure SCPs to prevent VPCs from gaining internet access. By denying access to all Regions except ap-northeast-3, the company ensures that VPCs can only be deployed in the specified Region. Option B is incorrect because using rules in AWS WAF alone does not address the requirement of denying access to all AWS Regions except ap-northeast-3. Option D is incorrect because configuring outbound rules in network ACLs and IAM policies for users can help restrict traffic and access, but it does not enforce the company's requirement of denying access to all Regions except ap-northeast-3. Option E is incorrect because using AWS Config and managed rules can help detect and alert for specific resources and configurations, but it does not directly enforce the restriction of internet access or deny access to specific Regions.
upvoted 14 times
...
ChymKuBoy
Most Recent 2 weeks, 2 days ago
Selected Answer: AC
AC for sure
upvoted 1 times
...
awsgeek75
5 months, 3 weeks ago
Selected Answer: AC
B: Irrelevant WAF D: This is confusing so I'll ignore it. E: Wrong product A: Control Tower can have residency guard rails and block internet access. C: SCP is like a duplicate of A IMHO but it stops admins from circumventing A as Org policies cannot be overridden by admins unless they are org admins. Too moany assumptions
upvoted 2 times
...
BrijMohan08
9 months, 3 weeks ago
Selected Answer: AC
A. Use AWS Control Tower to implement data residency guardrails to deny internet access and deny access to all AWS Regions except ap-northeast-3. C. Use AWS Organizations to configure service control policies (SCPs) that prevent VPCs from gaining internet access. Deny access to all AWS Regions except ap-northeast-3.
upvoted 2 times
...
TariqKipkemei
10 months ago
Selected Answer: AC
Use Control Tower to implement data residency guardrails and Service Control Policies (SCPS) to prevent VPCs from gaining internet access.
upvoted 1 times
...
Guru4Cloud
10 months, 3 weeks ago
Selected Answer: AC
AWS Control Tower guardrails and AWS Organizations SCPs provide centralized, automated mechanisms to enforce no internet connectivity for VPCs and restrict Region access to only ap-northeast-3.
upvoted 3 times
...
Abrar2022
1 year ago
Didn't know that SCPS (Service Control Policies) could be used to deny users internet access. Good to know. Always thought it's got controlling who can and can't access AWS Services.
upvoted 4 times
...
hicham0101
1 year, 2 months ago
Agree with Aand C https://aws.amazon.com/blogs/aws/new-for-aws-control-tower-region-deny-and-guardrails-to-help-you-meet-data-residency-requirements/
upvoted 1 times
...
yallahool
1 year, 2 months ago
I choose C and D. For control tower, it can't be A because ap-northeast-3 doesn't support it! Also, in the case of E, it is detection and warning, so it is difficult to prevent internet connection (although the view is a little obscure).
upvoted 1 times
michellemeloc
1 year, 2 months ago
I just check, now it's supported!!!
upvoted 2 times
...
...
notacert
1 year, 2 months ago
Selected Answer: AC
A and C
upvoted 1 times
...
datz
1 year, 3 months ago
Selected Answer: CD
C/D A - CANNOT BE!!! AWS Control Tower is not available in ap-northeast-3! Check your B- for sure no C - SCPS (Service Control Policies)- For sure D - Deny outbound rule to be place in prod and also IAM Policy to deny Users creating services in AP-Northeast3 E - it creates an alert, which means it happens but an alert is triggered. so I think it's not good either.
upvoted 2 times
darn
1 year, 2 months ago
False, Control Tower is in Osaka NorthEast 3 https://docs.aws.amazon.com/controltower/latest/userguide/region-how.html
upvoted 2 times
...
...
Kaireny54
1 year, 3 months ago
Selected Answer: CD
Control tower isn't available in AP-northeast-3 (only available in ap-northeast1 and 2 : https://www.aws-services.info/controltower.html) For answer E, it creates an alert, wich means it happens but an alert is triggered. so i think it's not good either. That's why i would go for C and D
upvoted 2 times
darn
1 year, 2 months ago
False, Control Tower is in Osaka NorthEast 3 https://docs.aws.amazon.com/controltower/latest/userguide/region-how.html
upvoted 1 times
...
darn
1 year, 2 months ago
same page you posted: ap-northeast-3 Asia Pacific (Osaka) 2023-04-20 https://aws.amazon.com/controltower
upvoted 1 times
...
Bmarodi
1 year, 1 month ago
It's availabe now on the same tink u pasted in earlier: ap-northeast-3 Asia Pacific (Osaka) 2023-04-20.
upvoted 1 times
...
...
WherecanIstart
1 year, 3 months ago
Selected Answer: CE
AWS Control tower is not available in ap-northeast-3! https://www.aws-services.info/controltower.html
upvoted 1 times
...
warioverde
1 year, 3 months ago
What's wrong with B?
upvoted 3 times
NSA_Poker
1 month, 3 weeks ago
Denying access to all AWS Regions except ap-northeast-3 in the AWS account settings cannot be enforced. Each individual account owner would have to configure this on trust. They could easily change it to allow themselves access beyond the Asia Pacific Region. So, instead you configure access controls across ALL accounts by using service control policies (SCPs). Apply to the root & it will apply to all OUs and accounts in the organization.
upvoted 1 times
...
...
AlessandraSAA
1 year, 3 months ago
Selected Answer: CE
A - CANNOT BE!!! AWS Control Tower is not available in ap-northeast-3! Check your consolle.
upvoted 4 times
...
moaaz86
1 year, 4 months ago
From ChatGPT :) Control Tower: Can Yes, AWS Control Tower can implement data residency guardrails to deny internet access and restrict access to AWS Regions except for one. To restrict access to AWS regions, you can create a guardrail using AWS Organizations to deny access to all AWS regions except for the one that you want to allow. This can be done by creating an organizational policy that restricts access to specific AWS services and resources based on region. Config: Can(not). Yes, AWS Config can help you enforce restrictions on internet access and control access to specific AWS Regions using AWS Config Rules. It's worth noting that AWS Config is a monitoring service that provides continuous assessment of your AWS resources against desired configurations. While AWS Config can alert you when a configuration change occurs, it cannot directly restrict access to resources or enforce specific policies. For that, you may need to use other AWS services such as AWS Identity and Access Management (IAM), AWS Firewall Manager, or AWS Organizations.
upvoted 3 times
ACloud_Guru15
8 months, 1 week ago
If we say AWS won't support Control Tower & config, it will simply agree by asking few more questions. Don't trust ChatGPT blindly
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
ex Want to SAVE BIG on Certification Exam Prep?
close
ex Unlock All Exams with ExamTopics Pro 75% Off
  • arrow Choose From 1000+ Exams
  • arrow Access to 10 Exams per Month
  • arrow PDF Format Available
  • arrow Inline Discussions
  • arrow No Captcha/Robot Checks
Limited Time Offer
Ends in