A security engineer managing AWS Organizations wants to validate that service control policies (SCPs) align with best practices. Which approach should the engineer use?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS IAM Access Analyzer to validate the policies and review the policy validation findings..
Why this is the answer
AWS IAM Access Analyzer includes a policy validation feature that can be used to check SCPs for adherence to best practices, such as identifying errors, warnings, and suggestions for improvement. This directly addresses the need to validate SCPs. Reviewing AWS Trusted Advisor checks is useful for general cost optimization, security, and performance, but it doesn't specifically validate the syntax or best practices of SCPs. AWS Audit Manager helps automate evidence collection for audits and compliance, but it's not designed for direct SCP validation. Ensuring Amazon Inspector agents are installed is for vulnerability management of EC2 instances, which is unrelated to SCP policy validation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed