A company is managing multiple AWS accounts using AWS Organizations. One of these accounts is used only for retaining logs in an Amazon S3 bucket. The company wants to make sure that compute resources cannot be used in the account. How can this be accomplished with the LEAST administrative effort?
A) Apply an IAM policy to all IAM entities in the account with a statement to explicitly deny NotAction: s3:*.
B) Configure AWS Config to terminate compute resources that have been created in the accounts.
C) Configure AWS CloudTrail to block any action where the event source is not s3:amazonaws.com.
D) Update the service control policy on the account to deny the unapproved services.
Correct Answer:
Verified
Q696: An application running on Amazon EC2 needs
Q697: A VPC is connected to a company
Q698: A company's Marketing department generates gigabytes of
Q699: A Security and Compliance team is reviewing
Q700: A SysOps Administrator observes a large number
Q702: A sysops administrator is trying to deploy
Q703: You need to design a VPC for
Q704: You have an Auto Scaling group associated
Q705: A SysOps administrator is evaluating Amazon Route
Q706: A company wants to reduce costs on
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents