SAP-C02 exam dumps

SAP-C02 practice question 224 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 224

Select 2

A company is building a multi-account AWS environment using AWS Organizations. The company wants to enforce a unified set of IAM policies across all accounts to ensure compliance. Additionally, the company wants to allow individual accounts to manage their own specific IAM roles and policies without impacting the uniform policies defined at the organization level. Which solution should the company implement?

  1. A

    Use Service Control Policies (SCPs) in AWS Organizations to define and enforce the unified policies across all accounts.

  2. B

    Use IAM Policies in the management account and apply them directly to the member accounts to enforce the unified policies.

  3. C

    Enable delegation of administrator permissions in AWS Organizations to allow member accounts to manage their own IAM roles and policies.

  4. D

    Create a common IAM policy in each member account manually and ensure it is consistent across all accounts.

  5. E

    Use AWS Config to monitor IAM compliance across all accounts and automatically remediate violations of the unified policy.

Show answer and explanation

Correct answers: A, C

Explanation

To enforce a unified set of IAM policies across all accounts in an AWS Organization while still allowing individual accounts to manage their own IAM roles and policies, Service Control Policies (SCPs) should be used. SCPs define organization-wide permission boundaries. By delegating administrator permissions, member accounts can manage their own IAM resources within the boundaries defined by the SCPs. Other options, such as directly applying IAM policies from the management account or manually maintaining consistency, are either not feasible or effective.

  • A. Correct.

    Service Control Policies (SCPs) are used in AWS Organizations to define and enforce permissions boundaries across all accounts, ensuring compliance with the unified policies. SCPs do not interfere with the ability of individual accounts to create their own IAM roles and policies within the defined boundaries.

  • B. Incorrect.

    IAM Policies cannot be directly applied from the management account to the member accounts. IAM Policies are account-specific and cannot enforce organization-wide restrictions.

  • C. Correct.

    By enabling delegation of administrator permissions in AWS Organizations, member accounts can manage their own IAM roles and policies without violating the SCP restrictions set at the organization level.

  • D. Incorrect.

    Manually creating a common IAM policy in each member account is error-prone and does not provide a centralized or enforceable mechanism to ensure compliance across all accounts.

  • E. Incorrect.

    AWS Config can monitor compliance and remediate violations, but it cannot enforce unified IAM policies across accounts. SCPs are specifically designed for this purpose.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam