A company uses multiple AWS accounts under AWS Organizations. There is an OU for production and another for development. Corporate rules permit developers to use only preapproved AWS services in the production account. What is the most operationally efficient way to enforce this restriction for the production account?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a service control policy (SCP) and attach it to the production OU..
Why this is the answer
Attaching a Service Control Policy (SCP) to the production OU is the most operationally efficient way to enforce this restriction. SCPs are a feature of AWS Organizations that allow you to centrally manage permissions across multiple accounts. When an SCP is attached to an OU, it applies to all accounts within that OU, including any new accounts created in the future. This ensures consistent enforcement of the allowed services without needing to manage individual policies per user or account. Creating a customer-managed IAM policy for all users in the production account would be cumbersome to manage, especially with a growing number of users or accounts. An IAM job function policy is still an IAM policy and would have the same management overhead. Enforcing an IAM policy through Amazon API Gateway is not relevant for restricting AWS service usage within an account; API Gateway controls access to APIs, not general AWS service permissions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed