SAP-C02 · Question #151
A company manages multiple AWS accounts by using AWS Organizations. Under the root OU. the company has two OUs: Research and DataOps. Because of regulatory requirements, all resources that the company
The correct answer is C. Create an SCP Use the aws:RequestedRegion condition key to restrict access to all AWS E. Create an SCP Use the ec2:lnstanceType condition key to restrict access to specific instance. https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examp
Question
A company manages multiple AWS accounts by using AWS Organizations. Under the root OU. the company has two OUs: Research and DataOps. Because of regulatory requirements, all resources that the company deploys in the organization must reside in the ap-northeast-1 Region. Additionally, EC2 instances that the company deploys in the DataOps OU must use a predefined list of instance types. A solutions architect must implement a solution that applies these restrictions. The solution must maximize operational efficiency and must minimize ongoing maintenance. Which combination of steps will meet these requirements? (Select TWO )
Options
- ACreate an IAM role in one account under the DataOps OU.
- BCreate an IAM user in all accounts under the root OU.
- CCreate an SCP Use the aws:RequestedRegion condition key to restrict access to all AWS
- DCreate an SCP Use the ec2 Region condition key to restrict access to all AWS Regions except
- ECreate an SCP Use the ec2:lnstanceType condition key to restrict access to specific instance
How the community answered
(25 responses)- A8% (2)
- B24% (6)
- C56% (14)
- D12% (3)
Explanation
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examp
Community Discussion
No community discussion yet for this question.