A large company has multiple AWS accounts that are assigned to each department. A SysOps administrator needs to help the company reduce overhead and manage its AWS resources more easily. The SysOps administrator also must ensure that department users, including AWS account root users, have access only to AWS services that are essential for their job function. Which solution will meet these requirements?
A) Enable AWS Directory Service. Enforce Group Policy Objects (GPOs) on each department to restrict access.
B) Migrate all the accounts to a central account. Create IAM groups for each department with only the necessary permissions.
C) Use AWS Organizations and implement service control policies (SCPs) to ensure accounts use only essential AWS services.
D) Use AWS Single Sign-On and configure it to limit access to only essential AWS services.
Correct Answer:
Verified
Q817: Each SysOps Administrator at a company has
Q818: A company wants to store sensitive data
Q819: A company wants to launch a group
Q820: A company runs a multi-tier web application
Q821: An organization is planning to create 5
Q823: A user is running a batch process
Q824: A user has configured ELB with two
Q825: A user has configured an Auto Scaling
Q826: An organization has launched 5 instances: 2
Q827: A security officer has requested that internet
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents