SAA-C03 · Question #709
A company creates an organization in AWS Organizations. The company creates organizational units (OUs) for production and non-production environments. The company does not want to allow accounts that
The correct answer is B. Create a service control policy (SCP) to deny the use of P5 EC2 instances. Attach the policy to. A service control policy can explicitly deny specific AWS API actions for accounts in an organizational unit. By denying the actions required to launch P5 GPU-enabled EC2 instances and attaching the policy to the non-production OU, accounts in that OU are prevented from using P5
Question
A company creates an organization in AWS Organizations. The company creates organizational units (OUs) for production and non-production environments. The company does not want to allow accounts that are in the non-production OU to create GPU-enabled P5 Amazon EC2 instances. However, the company does want to allow accounts in the production OU to use this type of EC2 instance. Which solution will meet these requirements?
Options
- ACreate an AI services opt-out policy. Attach the policy to the non-production OU.
- BCreate a service control policy (SCP) to deny the use of P5 EC2 instances. Attach the policy to
- CCreate an AI services opt-out policy. Attach the policy to the root of the organization and to the
- DCreate a service control policy (SCP) to allow the use of P5 EC2 instances. Attach the policy to
How the community answered
(17 responses)- A12% (2)
- B76% (13)
- C6% (1)
- D6% (1)
Explanation
A service control policy can explicitly deny specific AWS API actions for accounts in an organizational unit. By denying the actions required to launch P5 GPU-enabled EC2 instances and attaching the policy to the non-production OU, accounts in that OU are prevented from using P5 instances, while accounts in the production OU remain unaffected and can continue to use
Community Discussion
No community discussion yet for this question.