A company will split resources into hundreds of AWS accounts across multiple Regions and needs a solution that denies access to any operations outside specifically allowed Regions. Which approach satisfies this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy an AWS Control Tower landing zone, create Organizational Units (OUs) and attach Service Control Policies (SCPs) that deny running services outside the approved Regions..
Why this is the answer
The correct answer is to deploy an AWS Control Tower landing zone, create Organizational Units (OUs), and attach Service Control Policies (SCPs) that deny running services outside approved Regions. AWS Control Tower provides a well-architected multi-account environment, and SCPs, applied at the OU or root level, are a powerful way to enforce maximum permissions across all accounts within an organization. SCPs can effectively deny actions in specific Regions, ensuring compliance at an organizational level. Creating IAM roles with condition keys for each account is less scalable and harder to manage across hundreds of accounts. Creating IAM users with policies in each account is also not scalable and doesn't provide the centralized control needed for a large number of accounts. AWS Security Hub is a security posture management service; it identifies security findings but does not enforce or prevent resource deployment in specific Regions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed