nerdexam
Amazon

SCS-C02 · Question #49

A company is designing a multi-account structure for its development teams. The company is using AWS Organizations and AWS IAM Identity Center (AWS Single Sign-On). The company must implement a…

The correct answer is C. Create SCPs that include the Condition, Resource, and NotAction elements to allow access to. https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examp les_general.html#example-scp-deny-region

Submitted by obi.ng· Mar 6, 2026Management and Security Governance

Question

A company is designing a multi-account structure for its development teams. The company is using AWS Organizations and AWS IAM Identity Center (AWS Single Sign-On). The company must implement a solution so that the development teams can use only specific AWS Regions and so that each AWS account allows access to only specific AWS services. Which solution will meet these requirements with the LEAST operational overhead?

Options

  • AUse IAM Identity Center to set up service-linked roles with IAM policy statements that include the
  • BDeactivate AWS Security Token Service (AWS STS) in Regions that the developers are not
  • CCreate SCPs that include the Condition, Resource, and NotAction elements to allow access to
  • DFor each AWS account, create tailored identity-based policies for IAM Identity Center. Use

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    5% (1)
  • C
    77% (17)
  • D
    9% (2)

Explanation

https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examp les_general.html#example-scp-deny-region

Topics

#Service Control Policies#AWS Organizations#Region restrictions#service allow-listing

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice