nerdexam
Amazon

SAP-C02 · Question #151

A company manages multiple AWS accounts by using AWS Organizations. Under the root OU. the company has two OUs: Research and DataOps. Because of regulatory requirements, all resources that the company

The correct answer is C. Create an SCP Use the aws:RequestedRegion condition key to restrict access to all AWS E. Create an SCP Use the ec2:lnstanceType condition key to restrict access to specific instance. https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examp

Submitted by fernanda_arg· Mar 6, 2026Design Solutions for Organizational Complexity

Question

A company manages multiple AWS accounts by using AWS Organizations. Under the root OU. the company has two OUs: Research and DataOps. Because of regulatory requirements, all resources that the company deploys in the organization must reside in the ap-northeast-1 Region. Additionally, EC2 instances that the company deploys in the DataOps OU must use a predefined list of instance types. A solutions architect must implement a solution that applies these restrictions. The solution must maximize operational efficiency and must minimize ongoing maintenance. Which combination of steps will meet these requirements? (Select TWO )

Options

  • ACreate an IAM role in one account under the DataOps OU.
  • BCreate an IAM user in all accounts under the root OU.
  • CCreate an SCP Use the aws:RequestedRegion condition key to restrict access to all AWS
  • DCreate an SCP Use the ec2 Region condition key to restrict access to all AWS Regions except
  • ECreate an SCP Use the ec2:lnstanceType condition key to restrict access to specific instance

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    24% (6)
  • C
    56% (14)
  • D
    12% (3)

Explanation

https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examp

Community Discussion

No community discussion yet for this question.

Full SAP-C02 Practice