A company has multiple AWS accounts. The company uses AWS Organizations with an organizational unit (OU) for the production account and another OU for the development account. Corporate policies state that developers may use only approved AWS services in the production account. What is the MOST operationally efficient solution to control the production account?
A) Create a customer managed policy in AWS Identity and Access Management (IAM) . Apply the policy to all users within the production account.
B) Create a job function policy in AWS Identity and Access Management (IAM) . Apply the policy to all users within the production OU.
C) Create a service control policy (SCP) . Apply the SCP to the production OU.
D) Create an IAM policy. Apply the policy in Amazon API Gateway to restrict the production account.
Correct Answer:
Verified
Q796: A SysOps Administrator wants to prevent Developers
Q797: A SysOps Administrator must generate a report
Q798: A company is operating a multi-account environment
Q799: A company has an application database on
Q800: A company is releasing a new static
Q802: The Security team at AnyCompany discovers that
Q803: Developers are using IAM access keys to
Q804: A company's application infrastructure was deployed using
Q805: A SysOps administrator recently launched an application
Q806: A company is migrating its exchange server
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents