nerdexam
Amazon

SCS-C02 · Question #428

A company uses an organization in AWS Organizations to help separate its Amazon EC2 instances and VPCs. The company has separate OUs for development workloads and production workloads. A security engi

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #428. The question stem and answer options stay visible for context.

Submitted by mateo_ar· Mar 6, 2026Identity and Access Management

Question

A company uses an organization in AWS Organizations to help separate its Amazon EC2 instances and VPCs. The company has separate OUs for development workloads and production workloads. A security engineer must ensure that only AWS accounts in the production OU can write VPC flow logs to an Amazon S3 bucket. The security engineer is configuring the S3 bucket policy with a Condition element to allow the s3:PutObject action for VPC flow logs. How should the security engineer configure the Condition element to meet these requirements?

Options

  • ASet the value of the aws:SourceOrgID condition key to be the organization ID.
  • BSet the value of the aws:SourceOrgPaths condition key to be the Organizations entity path of the
  • CSet the value of the aws:ResourceOrgID condition key to be the organization ID.
  • DSet the value of the aws:ResourceOrgPaths condition key to be the Organizations entity path of

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#S3 bucket policy#aws:SourceOrgPaths#VPC flow logs#Organizations condition key
Full SCS-C02 Practice