nerdexam
Amazon

SOA-C02 · Question #675

A company is creating a new multi-account environment in AWS Organizations. The company will use AWS Control Tower to deploy the environment. Users must be able to create resources in approved AWS Reg

Sign in or unlock SOA-C02 to reveal the answer and full explanation for question #675. The question stem and answer options stay visible for context.

Submitted by carter_n· Mar 30, 2026Security and Compliance

Question

A company is creating a new multi-account environment in AWS Organizations. The company will use AWS Control Tower to deploy the environment. Users must be able to create resources in approved AWS Regions only. The company must configure and govern all accounts by using a standard baseline configuration. Which combination of steps will meet these requirements in the MOST operationally efficient way? (Choose two.)

Options

  • ACreate a permission set and a custom permissions policy in AWS IAM Identity Center for each
  • BDeploy AWS Config rules in each AWS account to govern the account's security compliance and
  • CDeploy AWS Lambda functions to configure security settings across all accounts in the
  • DImplement a service control policy (SCP) to deny any access to AWS based on the requested
  • EModify the AWS Control Tower landing zone settings to govern the approved Regions.

Unlock SOA-C02 to see the answer

You've previewed enough free SOA-C02 questions. Unlock SOA-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#AWS Control Tower#service control policies#AWS Organizations#multi-account governance
Full SOA-C02 Practice