A company is using AWS Organizations to manage all their accounts. The Chief Technology Officer wants to prevent certain services from being used within production accounts until the services have been internally certified. They are willing to allow developers to experiment with these uncertified services in development accounts but need a way to ensure that these services are not used within production accounts. Which option ensures that services are not allowed within the production accounts, yet are allowed in separate development accounts within the LEAST administrative overhead?
A) Use AWS Config to shut down non-compliant services found within the production accounts on a periodic basis, while allowing these same services to run in the development accounts.
B) Apply service control policies to the AWS Organizational Unit (OU) containing the production accounts to whitelist certified services. Apply a less restrictive policy to the OUs containing the development accounts.
C) Use IAM policies applied to the combination of user and account to prevent developers from using these services within the production accounts. Allow the services to run in development accounts.
D) Use Amazon CloudWatch to report on the use of non-certified services within any account, triggering an AWS Lambda function to terminate only those non-certified services when found in a production account.
Correct Answer:
Verified
Q851: An instance has enabled basic monitoring only
Q852: A company has a fleet of EC2
Q853: An Amazon EBS volume attached to an
Q854: A SysOps Administrator must ensure that AWS
Q855: Which instance characteristics are required if an
Q857: In IAM, can you attach more than
Q858: Which of the following services is offered
Q859: A user has created a VPC with
Q860: Network ACLs are _.
A) stateful
B) stateless
C) asynchronous
D)
Q861: A Development team is designing an application
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents