A company wants to ensure that the workloads for each of its business units have complete autonomy and a minimal blast radius in AWS. The Security team must be able to control access to the resources and services in the account to ensure that particular services are not used by the business units. How can a Solutions Architect achieve the isolation requirements?
A) Create individual accounts for each business unit and add the account to an OU in AWS Organizations. Modify the OU to ensure that the particular services are blocked. Federate each account with an IdP, and create separate roles for the business units and the Security team.
B) Create individual accounts for each business unit. Federate each account with an IdP and create separate roles and policies for business units and the Security team.
C) Create one shared account for the entire company. Create separate VPCs for each business unit. Create individual IAM policies and resource tags for each business unit. Federate each account with an IdP, and create separate roles for the business units and the Security team.
D) Create one shared account for the entire company. Create individual IAM policies and resource tags for each business unit. Federate the account with an IdP, and create separate roles for the business units and the Security team.
Correct Answer:
Verified
Q410: A Company had a security event whereby
Q411: A three-tier web application runs on Amazon
Q412: A company is finalizing the architecture for
Q413: The company Security team requires that all
Q414: A Solutions Architect must create a cost-effective
Q416: A company is running a high-user-volume media-sharing
Q417: A company with several AWS accounts is
Q418: A company is running a .NET three-tier
Q419: A Development team is deploying new APIs
Q420: A company is implementing a multi-account strategy;
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents