SAP-C02 exam dumps

SAP-C02 practice question 42 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 42

Select 2

Your company operates a multi-account AWS environment and has recently adopted AWS Organizations for centralized governance. You are tasked with ensuring that all accounts adhere to security best practices, including preventing unauthorized changes to IAM roles and ensuring that Amazon S3 buckets do not allow public access. Which combination of actions should you take to enforce these controls?

  1. A

    Use AWS Organizations Service Control Policies (SCPs) to deny actions that make IAM roles modifiable in member accounts.

  2. B

    Enable AWS Config in all accounts and set up AWS Config Rules to monitor public access configurations for S3 buckets.

  3. C

    Create a Lambda function in each account to programmatically remove public access from S3 buckets.

  4. D

    Use an AWS Organizations SCP to deny any S3 bucket policy that allows public access.

  5. E

    Enable AWS Shield Advanced to protect against public access to S3 buckets.

Show answer and explanation

Correct answers: A, B

Explanation

To prescribe security controls in a multi-account AWS environment, SCPs are best suited for organization-wide restrictions, such as denying modifications to IAM roles. AWS Config is ideal for monitoring and enforcing resource compliance, such as ensuring S3 buckets do not allow public access. Together, these tools effectively enforce security best practices across all accounts. Other options, like Lambda functions or AWS Shield Advanced, are either operationally inefficient or not relevant to the stated security objectives.

  • A. Correct.

    This is correct. SCPs are an effective way to enforce account-wide restrictions, such as denying the modification of IAM roles, across all member accounts in an AWS Organization.

  • B. Correct.

    This is correct. AWS Config can monitor and evaluate the configuration of AWS resources, such as ensuring S3 buckets comply with security rules to prevent public access.

  • C. Incorrect.

    This is incorrect. While a Lambda function can address specific security issues, it is not an ideal solution for enforcing organization-wide security controls. Additionally, this approach is operationally more complex and error-prone.

  • D. Incorrect.

    This is incorrect. SCPs cannot directly evaluate S3 bucket policies for public access. Instead, SCPs are used to restrict actions, not evaluate resource configurations.

  • E. Incorrect.

    This is incorrect. AWS Shield Advanced is used for DDoS protection and does not address public access to S3 buckets.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam