A company manages multiple AWS accounts with AWS Organizations. Regulatory rules require that specific member accounts be restricted to a predefined set of AWS Regions where resources can be deployed. Resource tagging must be enforced according to a group standard and managed centrally with minimal configuration. Which approach should a solutions architect use to implement these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Associate the specific member accounts with a new organizational unit (OU). Apply a tag policy and use a service control policy (SCP) with conditions to restrict Regions..
Why this is the answer
The correct approach is to associate the specific member accounts with a new Organizational Unit (OU), apply a tag policy, and use a Service Control Policy (SCP) with conditions to restrict Regions. This centralizes management and ensures compliance. SCPs are effective for restricting AWS service actions and resource deployments at the OU or account level, including region restrictions. Tag policies enforce tagging standards across accounts. Incorrect options: Creating AWS Config rules in each member account is not centralized and requires individual configuration, which is not minimal. Disabling Regions from the AWS Billing and Cost Management console does not exist as a feature. Tag policies are applied at the root or OU level, not through billing. Associating accounts with the root directly would apply the SCP and tag policy to all accounts under the root, not just the specific ones, making it too broad. Using an OU allows for granular control over specific accounts.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed