SOA-C02 exam dumps

SOA-C02 practice question 171 of 341

AWS Certified SysOps Administrator - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

SOA-C02 Question 171

Single answer

A company uses AWS Organizations to manage multiple AWS accounts. The Security team wants to ensure that no IAM user can create access keys in any of the accounts, including the root account. How can the SysOps Administrator enforce this policy across all accounts?

  1. A

    Create a Service Control Policy (SCP) at the root of the organization to deny the 'iam:CreateAccessKey' action for all users.

  2. B

    Enable AWS Config in all accounts and configure a rule to detect and delete access keys when created.

  3. C

    Use AWS Identity Center (AWS Single Sign-On) to replace IAM users and disable access key creation by default.

  4. D

    Manually create an IAM policy in each account that denies the 'iam:CreateAccessKey' action and attach it to all IAM users.

Show answer and explanation

Correct answer: A

Explanation

To enforce security and compliance across multiple AWS accounts managed by AWS Organizations, SCPs are the recommended approach. SCPs allow you to define and enforce policies at the organization or account level. In this scenario, using an SCP to deny the 'iam:CreateAccessKey' action ensures that no IAM user or root account can create access keys, thereby enhancing security and compliance.

  • A. Correct.

    This is the correct answer. A Service Control Policy (SCP) can be applied at the organization level to enforce restrictions across all accounts. By denying the 'iam:CreateAccessKey' action at the organization level, IAM users and root users cannot create access keys.

  • B. Incorrect.

    This is incorrect because AWS Config can only detect non-compliance but cannot enforce restrictions or prevent the creation of access keys.

  • C. Incorrect.

    This is incorrect because AWS Identity Center (AWS Single Sign-On) is a service for managing user access but does not directly affect IAM user permissions or prevent access key creation.

  • D. Incorrect.

    This is incorrect because manually creating IAM policies in each account is cumbersome, error-prone, and does not enforce restrictions for root accounts.

Timed practice exam

Take a SOA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam