nerdexam
Amazon

SAP-C02 · Question #553

A company manages hundreds of AWS accounts centrally in an organization in AWS Organizations. The company recently started to allow product teams to create and manage their own S3 access points in…

The correct answer is B. Create an SCP at the root level in the organization to deny the s3:CreateAccessPoint action. https://aws.amazon.com/blogs/storage/managing-amazon-s3-access-with-vpc-endpoints-and-s3-

Submitted by omar99· Mar 6, 2026Design Solutions for Organizational Complexity

Question

A company manages hundreds of AWS accounts centrally in an organization in AWS Organizations. The company recently started to allow product teams to create and manage their own S3 access points in their accounts. The S3 access points can be accessed only within VPCs, not on the internet. What is the MOST operationally efficient way to enforce this requirement?

Options

  • ASet the S3 access point resource policy to deny the s3:CreateAccessPoint action unless the
  • BCreate an SCP at the root level in the organization to deny the s3:CreateAccessPoint action
  • CUse AWS CloudFormation StackSets to create a new IAM policy in each AWS account that
  • DSet the S3 bucket policy to deny the s3:CreateAccessPoint action unless the

How the community answered

(51 responses)
  • A
    10% (5)
  • B
    61% (31)
  • C
    6% (3)
  • D
    24% (12)

Explanation

https://aws.amazon.com/blogs/storage/managing-amazon-s3-access-with-vpc-endpoints-and-s3-

Community Discussion

No community discussion yet for this question.

Full SAP-C02 Practice