SAP-C02 exam dumps

SAP-C02 practice question 621 of 678

AWS Certified Solutions Architect - Professional. Professional level, Amazon Web Services. Free question with the correct answer and a full explanation.

SAP-C02 Question 621

Select 3

An organization is designing a multi-account AWS environment to manage multiple teams and projects. They want to enforce governance while allowing teams to operate independently. Which strategy ensures that compliance policies are enforced across accounts while still providing flexibility for teams to create and manage their resources within their own accounts?

  1. A

    Use AWS Organizations with Service Control Policies (SCPs) to manage permissions across accounts.

  2. B

    Set up AWS Config Rules and Aggregate Compliance Data in a centralized account.

  3. C

    Enable cross-account IAM roles to allow teams to access resources in other accounts freely.

  4. D

    Implement a shared VPC architecture across all accounts for consistent network management.

  5. E

    Leverage AWS Control Tower to automate account provisioning and governance.

Show answer and explanation

Correct answers: A, B, E

Explanation

To ensure governance and compliance across multiple AWS accounts while allowing teams to operate independently, you can leverage AWS Organizations with SCPs to enforce permissions, use AWS Config to track compliance, and utilize AWS Control Tower to automate account setup and governance. These tools together provide a robust strategy for managing a multi-account environment effectively.

  • A. Correct.

    Service Control Policies (SCPs) in AWS Organizations allow you to centrally manage permissions and enforce compliance across accounts. This ensures that no account can exceed defined permissions while still allowing teams to manage resources within their boundaries.

  • B. Correct.

    AWS Config Rules can be used to evaluate the compliance of resources, and aggregating compliance data in a centralized account provides visibility into the overall compliance posture across all accounts.

  • C. Incorrect.

    Allowing cross-account IAM roles without restrictions could lead to security risks and lack of governance. This does not enforce compliance but rather introduces potential vulnerabilities.

  • D. Incorrect.

    Using a shared VPC architecture might help with network management but does not inherently enforce compliance or provide governance across accounts.

  • E. Correct.

    AWS Control Tower provides a prescriptive way to set up and govern a secure multi-account environment. It automates compliance and enforces guardrails while giving teams the flexibility to operate within their accounts.

Timed practice exam

Take a SAP-C02 practice test under exam conditions

75 questions in 180 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam