nerdexam
Amazon

SOA-C02 · Question #533

A company has several member accounts that are in an organization in AWS Organizations. The company recently discovered that administrators have been using account root user credentials. The company…

The correct answer is B. In the organization's management account, create a service control policy (SCP) to deny actions. https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html

Submitted by yuki_2020· Mar 30, 2026Security and Compliance

Question

A company has several member accounts that are in an organization in AWS Organizations. The company recently discovered that administrators have been using account root user credentials. The company must prevent the administrators from using root user credentials to perform any actions on Amazon EC2 instances. What should a SysOps administrator do to meet this requirement?

Options

  • ACreate an identity-based IAM policy in each member account to deny actions on EC2 instances
  • BIn the organization's management account, create a service control policy (SCP) to deny actions
  • CUse AWS Config to prevent any actions on EC2 instances by the root user.
  • DUse Amazon Inspector in each member account to scan for root user logins and to prevent any

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    72% (13)
  • C
    6% (1)
  • D
    17% (3)

Explanation

https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps.html

Topics

#AWS Organizations#SCP#root user restriction#IAM policy

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice