Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam AWS Certified Solutions Architect - Associate SAA-C03 All Questions

View all questions & answers for the AWS Certified Solutions Architect - Associate SAA-C03 exam

Exam AWS Certified Solutions Architect - Associate SAA-C03 topic 1 question 168 discussion

A security team wants to limit access to specific services or actions in all of the team’s AWS accounts. All accounts belong to a large organization in AWS Organizations. The solution must be scalable and there must be a single point where permissions can be maintained.

What should a solutions architect do to accomplish this?

  • A. Create an ACL to provide access to the services or actions.
  • B. Create a security group to allow accounts and attach it to user groups.
  • C. Create cross-account roles in each account to deny access to the services or actions.
  • D. Create a service control policy in the root organizational unit to deny access to the services or actions.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nigma
Highly Voted 2 years ago
D. Service control policies (SCPs) are one type of policy that you can use to manage your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization, allowing you to ensure your accounts stay within your organization's access control guidelines. See https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scp.html.
upvoted 20 times
...
cookieMr
Highly Voted 1 year, 4 months ago
By creating an SCP in the root organizational unit, the security team can define and enforce fine-grained permissions that limit access to specific services or actions across all member accounts. The SCP acts as a guardrail, denying access to specified services or actions, ensuring that the permissions are consistent and applied uniformly across the organization. SCPs are scalable and provide a single point of control for managing permissions, allowing the security team to centrally manage access restrictions without needing to modify individual account settings. Option A and option B are not suitable for controlling access across multiple accounts in AWS Organizations. ACLs and security groups are typically used for managing network traffic and access within a single account or a specific resource. Option C is not the recommended approach. Cross-account roles are used for granting access, and denying access through cross-account roles can be complex and less manageable compared to using SCPs.
upvoted 10 times
awashenko
1 year, 1 month ago
This was a good explanation of why A and B are not correct. I was thinking A but after reading this I agree with you D is correct.
upvoted 2 times
...
...
PaulGa
Most Recent 3 weeks, 4 days ago
Selected Answer: D
Ans D - "A service control policy in the root organizational unit to deny access to the services or actions" does it at source
upvoted 2 times
...
Ruffyit
11 months, 3 weeks ago
D. Service control policies (SCPs) are one type of policy that you can use to manage your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization, allowing you to ensure your accounts stay within your organization's access control guidelines. See https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scp.html.
upvoted 2 times
...
mach2022
1 year ago
is D because of Deeznuts
upvoted 2 times
the_bong_lord
10 months ago
gottem
upvoted 1 times
...
...
xplusfb
1 year, 1 month ago
Selected Answer: D
Its very clear question answer is D
upvoted 3 times
...
TariqKipkemei
1 year, 2 months ago
Selected Answer: D
Service control policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization. SCPs help you to ensure your accounts stay within your organization’s access control guidelines.
upvoted 2 times
...
Guru4Cloud
1 year, 3 months ago
Selected Answer: D
D. Service control policies (SCPs) are one type of policy that you can use to manage your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization, allowing you to ensure your accounts stay within your organization's access control guidelines. See https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scp.html.
upvoted 2 times
...
Bmarodi
1 year, 6 months ago
Selected Answer: D
I vote for option D by Creating a service control policy ( SCP) in the root organizational unit to deny access to the services or actions, meets the requirements.
upvoted 2 times
...
Buruguduystunstugudunstuy
1 year, 11 months ago
Selected Answer: D
To limit access to specific services or actions in all of the team's AWS accounts and maintain a single point where permissions can be managed, the solutions architect should create a service control policy (SCP) in the root organizational unit to deny access to the services or actions (Option D). Service control policies (SCPs) are policies that you can use to set fine-grained permissions for your AWS accounts within your organization. SCPs are attached to the root of the organizational unit (OU) or to individual accounts, and they specify the permissions that are allowed or denied for the accounts within the scope of the policy. By creating an SCP in the root organizational unit, the security team can set permissions for all of the accounts in the organization from a single location, ensuring that the permissions are consistently applied across all accounts.
upvoted 5 times
...
career360guru
1 year, 11 months ago
Selected Answer: D
Option D
upvoted 1 times
...
Wpcorgan
1 year, 12 months ago
D iscorrect
upvoted 1 times
...
babaxoxo
2 years ago
an organization and requires single point place to manage permissions
upvoted 2 times
...
goatbernard
2 years ago
Selected Answer: D
SCP for organization
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...