nerdexam
Amazon

SAP-C02 · Question #86

A company is in the process of implementing AWS Organizations to constrain its developers to use only Amazon EC2, Amazon S3, and Amazon DynamoDB. The developers account resides in a dedicated organiza

Sign in or unlock SAP-C02 to reveal the answer and full explanation for question #86. The question stem and answer options stay visible for context.

Submitted by mateo_ar· Mar 6, 2026Design Solutions for Organizational Complexity

Question

A company is in the process of implementing AWS Organizations to constrain its developers to use only Amazon EC2, Amazon S3, and Amazon DynamoDB. The developers account resides in a dedicated organizational unit (OU). The solutions architect has implemented the following SCP on the developers account:

When this policy is deployed, IAM users in the developers account are still able to use AWS services that are not listed in the policy. What should the solutions architect do to eliminate the developers' ability to use services outside the scope of this policy?

Exhibit

SAP-C02 question #86 exhibit

Options

  • ACreate an explicit deny statement for each AWS service that should be constrained.
  • BRemove the FullAWSAccess SCP from the Developer account's OU.
  • CModify the FullAWSAccess SCP to explicitly deny all services.
  • DAdd an explicit deny statement using a wildcard to the end of the SCP.

Unlock SAP-C02 to see the answer

You've previewed enough free SAP-C02 questions. Unlock SAP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full SAP-C02 Practice