CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 17: AWS Certified Solutions Architect - Professional SAP-C02(New)

A company is in the process of implementing AWS Organizations to constrain its developers to use only Amazon EC2, Amazon S3, and Amazon DynamoDB. The developers account resides in a dedicated organizational unit (OU). The solutions architect has implemented the following SCP on the developers account: When this policy…

Nội dung câu hỏi

A company is in the process of implementing AWS Organizations to constrain its developers to use only Amazon EC2, Amazon S3, and Amazon DynamoDB. The developers account resides in a dedicated organizational unit (OU). The solutions architect has implemented the following SCP on the developers account: When this policy is deployed, IAM users in the developers account are still able to use AWS services that are not listed in the policy. What should the solutions architect do to eliminate the developers’ ability to use services outside the scope of this policy?

Minh họa câu hỏi

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Create an explicit deny statement for each AWS service that should be constrained.
  2. B. Remove the FullAWSAccess SCP from the developers account’s OU. — đáp án hiện tại
  3. C. Modify the FullAWSAccess SCP to explicitly deny all services.
  4. D. Add an explicit deny statement using a wildcard to the end of the SCP.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề