nerdexam
Amazon

SAA-C03 · Question #709

A company creates an organization in AWS Organizations. The company creates organizational units (OUs) for production and non-production environments. The company does not want to allow accounts that

The correct answer is B. Create a service control policy (SCP) to deny the use of P5 EC2 instances. Attach the policy to. A service control policy can explicitly deny specific AWS API actions for accounts in an organizational unit. By denying the actions required to launch P5 GPU-enabled EC2 instances and attaching the policy to the non-production OU, accounts in that OU are prevented from using P5

Submitted by chiamaka_o· Mar 4, 2026Design Secure Architectures

Question

A company creates an organization in AWS Organizations. The company creates organizational units (OUs) for production and non-production environments. The company does not want to allow accounts that are in the non-production OU to create GPU-enabled P5 Amazon EC2 instances. However, the company does want to allow accounts in the production OU to use this type of EC2 instance. Which solution will meet these requirements?

Options

  • ACreate an AI services opt-out policy. Attach the policy to the non-production OU.
  • BCreate a service control policy (SCP) to deny the use of P5 EC2 instances. Attach the policy to
  • CCreate an AI services opt-out policy. Attach the policy to the root of the organization and to the
  • DCreate a service control policy (SCP) to allow the use of P5 EC2 instances. Attach the policy to

How the community answered

(17 responses)
  • A
    12% (2)
  • B
    76% (13)
  • C
    6% (1)
  • D
    6% (1)

Explanation

A service control policy can explicitly deny specific AWS API actions for accounts in an organizational unit. By denying the actions required to launch P5 GPU-enabled EC2 instances and attaching the policy to the non-production OU, accounts in that OU are prevented from using P5 instances, while accounts in the production OU remain unaffected and can continue to use

Community Discussion

No community discussion yet for this question.

Full SAA-C03 Practice