nerdexam
Amazon

SCS-C02 · Question #241

A security administrator is restricting the capabilities of company root user accounts. The company uses AWS Organizations and has all features enabled. The management account is used for billing and

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #241. The question stem and answer options stay visible for context.

Submitted by mike_84· Mar 6, 2026Management and Security Governance

Question

A security administrator is restricting the capabilities of company root user accounts. The company uses AWS Organizations and has all features enabled. The management account is used for billing and administrative purposes, but it is not used for operational AWS resource purposes. How can the security administrator restrict usage of member root user accounts across the organization?

Options

  • ADisable the use of the root user account at the organizational root. Enable multi-factor
  • BConfigure IAM user policies to restrict root account capabilities for each organization member
  • CCreate an OU in Organizations, and attach an SCP that controls usage of the root user. Add all
  • DConfigure AWS CloudTrail to integrate with Amazon CloudWatch Logs Create a metric filter for

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#root user restriction#SCP#AWS Organizations#organizational units
Full SCS-C02 Practice