SCS-C02 exam dumps

SCS-C02 practice question 433 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 433

Single answer

An organization has implemented AWS Control Tower to manage multiple accounts within their AWS Organization. The security team wants to ensure that no user can create resources outside of the approved AWS Regions. Which approach should they take to enforce this requirement using policy-defined guardrails?

  1. A

    Enable the 'Disallow Configuring Resources Globally' mandatory guardrail in AWS Control Tower.

  2. B

    Enable the 'Disallow Creation of Resources in Unapproved Regions' elective guardrail in AWS Control Tower.

  3. C

    Create an SCP (Service Control Policy) in AWS Organizations to deny actions in unapproved Regions.

  4. D

    Use AWS Config to monitor resource creation events and send alerts for violations in unapproved Regions.

Show answer and explanation

Correct answer: C

Explanation

To enforce a restriction on creating resources outside of approved AWS Regions, Service Control Policies (SCPs) are the most appropriate mechanism. SCPs allow administrators to define guardrails at the organizational level, ensuring that policies are enforced across all accounts within the organization. AWS Config, while useful for monitoring and alerting, is insufficient for enforcement. Similarly, AWS Control Tower's predefined guardrails do not specifically include one that restricts resource creation based on Region in this context.

  • A. Incorrect.

    This is incorrect because there is no guardrail called 'Disallow Configuring Resources Globally.' Guardrails are specific, predefined policies in AWS Control Tower, and this option does not apply to the scenario.

  • B. Incorrect.

    This is incorrect because there is no specific elective guardrail named 'Disallow Creation of Resources in Unapproved Regions' in AWS Control Tower. Elective guardrails may help in maintaining compliance but cannot enforce the restriction discussed in the scenario.

  • C. Correct.

    This is correct because Service Control Policies (SCPs) allow you to enforce restrictions across your AWS Organization. By creating an SCP that denies specific actions in unapproved Regions, you can effectively achieve the desired enforcement.

  • D. Incorrect.

    This is incorrect because AWS Config is primarily a monitoring and compliance tool. While it can detect violations and send alerts, it does not directly enforce restrictions, which is the requirement in this scenario.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam