SAP-C02 exam dumps

SAP-C02 practice question 398 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 398

Single answer

Your company has an AWS environment hosting multiple applications across different accounts, all managed under AWS Organizations. Security audits have revealed that some accounts have overly permissive IAM policies granting access to sensitive resources. To address this issue, the security team wants to implement a centralized solution to enforce security best practices and ensure compliance across all accounts. What is the most effective strategy you should recommend?

  1. A

    Set up AWS Config rules in each account to monitor and remediate overly permissive IAM policies.

  2. B

    Implement Service Control Policies (SCPs) at the AWS Organizations level to restrict overly permissive actions across all accounts.

  3. C

    Enable AWS CloudTrail in each account and analyze logs to manually identify and fix overly permissive IAM policies.

  4. D

    Use IAM Access Analyzer in each account to automatically flag overly permissive IAM policies and remediate them manually.

Show answer and explanation

Correct answer: B

Explanation

Service Control Policies (SCPs) are the best solution for enforcing security best practices in a multi-account AWS environment managed under AWS Organizations. SCPs allow administrators to define permission guardrails that are applied to all accounts within the organization, ensuring that overly permissive IAM policies are restricted and compliance is maintained centrally.

  • A. Incorrect.

    While AWS Config can monitor and remediate issues, setting up and maintaining rules in each account is operationally complex. This does not provide centralized enforcement across multiple accounts.

  • B. Correct.

    Service Control Policies (SCPs) are designed specifically for centrally managing permissions across AWS accounts in an Organization. They enforce security best practices by restricting actions at the organizational level, making them ideal for addressing overly permissive policies.

  • C. Incorrect.

    CloudTrail logs provide valuable information for auditing, but manually analyzing logs and fixing IAM policies is time-consuming and error-prone. This is not a scalable solution for a multi-account architecture.

  • D. Incorrect.

    IAM Access Analyzer can flag overly permissive policies in an account, but this approach requires manual effort in each account and does not enforce centralized restrictions.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam