SAP-C02 exam dumps

SAP-C02 practice question 109 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 109

Select 2

You are a Solutions Architect working for a large enterprise that recently adopted AWS Control Tower to standardize governance across multiple AWS accounts. The enterprise already uses AWS Organizations with several Organizational Units (OUs) and Service Control Policies (SCPs) in place. After enabling AWS Control Tower, you realize that some SCPs are not being enforced as expected. What steps should you take to resolve this issue?

  1. A

    Review the AWS Control Tower guardrails and ensure they do not conflict with the SCPs.

  2. B

    Manually re-attach the SCPs to the Organizational Units (OUs) after enabling Control Tower.

  3. C

    Verify that the affected accounts in the OU are enrolled in AWS Control Tower.

  4. D

    Re-enable AWS Control Tower to re-sync the SCPs with the guardrails.

  5. E

    Ensure that the permissions boundary set in AWS Control Tower does not override the SCP restrictions.

Show answer and explanation

Correct answers: A, C

Explanation

AWS Control Tower applies its own governance rules and guardrails, which may conflict with existing SCPs configured in AWS Organizations. To ensure proper enforcement of SCPs, it is crucial to review potential conflicts between SCPs and guardrails. Additionally, for SCPs and guardrails to take effect on specific accounts, those accounts must be enrolled in AWS Control Tower. Understanding these interactions helps maintain consistent governance across your AWS environment.

  • A. Correct.

    Reviewing AWS Control Tower guardrails is important because they may introduce governance configurations that could conflict with existing SCPs. AWS Control Tower applies its own set of guardrails, which might override or conflict with custom SCPs.

  • B. Incorrect.

    Re-attaching SCPs manually is not required because SCPs remain attached to OUs in AWS Organizations, even after enabling AWS Control Tower. AWS Control Tower does not automatically remove these SCPs.

  • C. Correct.

    Accounts must be enrolled in AWS Control Tower for its governance policies and guardrails to be fully applied. If an account is not enrolled, the SCPs may not be enforced as expected.

  • D. Incorrect.

    Re-enabling AWS Control Tower is not a valid operation for resolving SCP enforcement issues. AWS Control Tower does not support such an action, and SCPs are managed independently within AWS Organizations.

  • E. Incorrect.

    AWS Control Tower does not use permissions boundaries to override SCPs. Permissions boundaries are a different IAM feature and are unrelated to SCP enforcement.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam