Amazon
SOA-C02 · Question #533
A company has several member accounts that are in an organization in AWS Organizations. The company recently discovered that administrators have been using account root user credentials. The company…
The correct answer is B. In the organization's management account, create a service control policy (SCP) to deny actions. https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html
Submitted by yuki_2020· Mar 30, 2026Security and Compliance
Question
A company has several member accounts that are in an organization in AWS Organizations. The company recently discovered that administrators have been using account root user credentials. The company must prevent the administrators from using root user credentials to perform any actions on Amazon EC2 instances. What should a SysOps administrator do to meet this requirement?
Options
- ACreate an identity-based IAM policy in each member account to deny actions on EC2 instances
- BIn the organization's management account, create a service control policy (SCP) to deny actions
- CUse AWS Config to prevent any actions on EC2 instances by the root user.
- DUse Amazon Inspector in each member account to scan for root user logins and to prevent any
How the community answered
(18 responses)- A6% (1)
- B72% (13)
- C6% (1)
- D17% (3)
Explanation
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html
Topics
#AWS Organizations#SCP#root user restriction#IAM policy
Community Discussion
No community discussion yet for this question.