nerdexam
Amazon

SCS-C03 · Question #91

A company has an organization in AWS Organizations. The organization consists of multiple OUs. The company must prevent IAM principals from outside the organization from accessing the organization's A

Sign in or unlock SCS-C03 to reveal the answer and full explanation for question #91. The question stem and answer options stay visible for context.

Submitted by ravi_2018· Mar 6, 2026Identity and Access Management (IAM)

Question

A company has an organization in AWS Organizations. The organization consists of multiple OUs. The company must prevent IAM principals from outside the organization from accessing the organization's Amazon S3 buckets. The solution must not affect the existing access that the OUs have to the S3 buckets. Which solution will meet these requirements?

Options

  • AConfigure S3 Block Public Access for all S3 buckets.
  • BConfigure S3 Block Public Access for all AWS accounts.
  • CDeploy an SCP that includes the "aws:ResourceOrgPaths": "${aws:PrincipalOrgPaths}" condition.
  • DDeploy an SCP that includes the "aws:ResourceOrgID": "${aws:PrincipalOrgID}" condition.

Unlock SCS-C03 to see the answer

You've previewed enough free SCS-C03 questions. Unlock SCS-C03 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#SCP#AWS Organizations#PrincipalOrgID#S3 cross-org access
Full SCS-C03 Practice