nerdexam
Amazon

SAP-C02 · Question #449

A company has 10 accounts that are part of an organization in AWS Organizations AWS Config is configured in each account. All accounts belong to either the Prod OU or the NonProd OU. The company has s

Sign in or unlock SAP-C02 to reveal the answer and full explanation for question #449. The question stem and answer options stay visible for context.

Submitted by layla.eg· Mar 6, 2026Design Solutions for Organizational Complexity

Question

A company has 10 accounts that are part of an organization in AWS Organizations AWS Config is configured in each account. All accounts belong to either the Prod OU or the NonProd OU. The company has set up an Amazon EventBridge rule in each AWS account to notify an Amazon Simple Notification Service (Amazon SNS) topic when an Amazon EC2 security group inbound rule is created with 0.0.0.0/0 as the source. The company's security team is subscribed to the SNS topic. For all accounts in the NonProd OU the security team needs to remove the ability to create a security group inbound rule that includes 0.0.0.0/0 as the source. Which solution will meet this requirement with the LEAST operational overhead?

Options

  • AModify the EventBridge rule to invoke an AWS Lambda function to remove the security group
  • BAdd the vpc-sg-open-only-to-authorized-ports AWS Config managed rule to the NonProd OU.
  • CConfigure an SCP to allow the ec2 AulhonzeSecurityGrouplngress action when the value of the
  • DConfigure an SCP to deny the ec2 AuthorizeSecurityGrouplngress action when the value of the

Unlock SAP-C02 to see the answer

You've previewed enough free SAP-C02 questions. Unlock SAP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SAP-C02 Practice