A company uses multiple AWS accounts for production and non-production workloads across DevOps teams. They want to centrally restrict access to a small set of AWS services that DevOps teams do not use, while allowing access to services currently in use. They already invited all accounts into AWS Organizations. They also want to administer groups of accounts together. Which combination of actions should a solutions architect take? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Adopt a deny-list (explicit deny) strategy for services to restrict access., Use IAM Access Advisor to review which services have been used recently by principals., Create organizational units (OUs) and move member accounts into the appropriate OUs..
Why this is the answer
A deny-list strategy is appropriate here because the company wants to restrict access to a small set of unused services, while allowing access to most services. An explicit deny ensures these specific services cannot be used. IAM Access Advisor helps identify which services principals have actually used, providing data to inform which services can be safely restricted without impacting current operations. Creating Organizational Units (OUs) allows for grouping accounts (e.g., production vs. non-production) to apply Service Control Policies (SCPs) to groups of accounts, fulfilling the requirement to administer groups of accounts together. AWS Trusted Advisor reports focus on cost optimization, security, and performance, not service usage by principals. Removing the default FullAWSAccess SCP would severely restrict all accounts, which is not the goal. There is no default DenyAWSAccess SCP.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed