nerdexam
Amazon

SOA-C02 · Question #675

A company is creating a new multi-account environment in AWS Organizations. The company will use AWS Control Tower to deploy the environment. Users must be able to create resources in approved AWS…

The correct answer is D. Implement a service control policy (SCP) to deny any access to AWS based on the requested E. Modify the AWS Control Tower landing zone settings to govern the approved Regions. To enforce resource creation only in approved AWS Regions while ensuring a standardized baseline configuration across accounts, the most operationally efficient approach is: 1. Use Service Control Policies (SCPs) SCPs are applied at the organization level in AWS Organizations…

Submitted by carter_n· Mar 30, 2026Security and Compliance

Question

A company is creating a new multi-account environment in AWS Organizations. The company will use AWS Control Tower to deploy the environment. Users must be able to create resources in approved AWS Regions only. The company must configure and govern all accounts by using a standard baseline configuration. Which combination of steps will meet these requirements in the MOST operationally efficient way? (Choose two.)

Options

  • ACreate a permission set and a custom permissions policy in AWS IAM Identity Center for each
  • BDeploy AWS Config rules in each AWS account to govern the account's security compliance and
  • CDeploy AWS Lambda functions to configure security settings across all accounts in the
  • DImplement a service control policy (SCP) to deny any access to AWS based on the requested
  • EModify the AWS Control Tower landing zone settings to govern the approved Regions.

How the community answered

(34 responses)
  • A
    18% (6)
  • B
    6% (2)
  • C
    3% (1)
  • D
    74% (25)

Explanation

To enforce resource creation only in approved AWS Regions while ensuring a standardized baseline configuration across accounts, the most operationally efficient approach is: 1. Use Service Control Policies (SCPs) SCPs are applied at the organization level in AWS Organizations and can restrict resource creation in unapproved AWS Regions across all accounts. This is an efficient way to enforce policies without needing to configure each account individually. 2. Modify AWS Control Tower Landing Zone settings AWS Control Tower provides governance across multiple accounts and enforces Region restrictions as part of its setup. Using AWS Control Tower landing zone settings, administrators can define approved Regions to ensure resources are deployed only in those Regions.

Topics

#AWS Control Tower#service control policies#AWS Organizations#multi-account governance

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice