nerdexam
Amazon

SCS-C02 · Question #18

A security engineer is using AWS Organizations and wants to optimize SCPs. The security engineer needs to ensure that the SCPs conform to best practices. Which approach should the security engineer ta

The correct answer is A. Use AWS IAM Access Analyzer to analyze the polices. View the findings from policy validation. You can create AWS IAM Access Analyzer in AWS Organizations as the zone of trust. https://aws.amazon.com/blogs/aws/new-use-aws-iam-access-analyzer-in-aws-organizations/

Submitted by kim_seoul· Mar 6, 2026Management and Security Governance

Question

A security engineer is using AWS Organizations and wants to optimize SCPs. The security engineer needs to ensure that the SCPs conform to best practices. Which approach should the security engineer take to meet this requirement?

Options

  • AUse AWS IAM Access Analyzer to analyze the polices. View the findings from policy validation
  • BReview AWS Trusted Advisor checks for all accounts in the organization.
  • CSet up AWS Audit Manager. Run an assessment for all AWS Regions for all accounts.
  • DEnsure that Amazon Inspector agents are installed on all Amazon EC2 instances in all accounts.

How the community answered

(24 responses)
  • A
    75% (18)
  • B
    17% (4)
  • C
    4% (1)
  • D
    4% (1)

Explanation

You can create AWS IAM Access Analyzer in AWS Organizations as the zone of trust. https://aws.amazon.com/blogs/aws/new-use-aws-iam-access-analyzer-in-aws-organizations/

Topics

#SCP#IAM Access Analyzer#policy validation#Organizations

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice