A company is setting up a multi-account environment with AWS Organizations and AWS IAM Identity Center (AWS Single Sign-On). The company must restrict development teams to specific AWS Regions and restrict each account to only approved AWS services, with the least operational overhead. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create service control policies (SCPs) that use Condition, Resource, and NotAction elements to allow only the required Regions and services..
Why this is the answer
The correct solution is to create service control policies (SCPs) that use Condition, Resource, and NotAction elements to allow only the required Regions and services. SCPs are a feature of AWS Organizations that enable you to manage permissions in all accounts in your organization. They are ideal for setting guardrails, like restricting AWS Regions and approved services, across multiple accounts with minimal operational overhead because they apply centrally. Using IAM Identity Center to create service-linked roles or custom IAM Identity Center identity-based policies for each account would be operationally intensive and difficult to maintain across a multi-account environment. Disabling AWS Security Token Service (AWS STS) in specific Regions is not a practical or recommended method for restricting access, as STS is fundamental for authentication and authorization across AWS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed