Administrators across multiple member accounts in an AWS Organization — including those who have root credentials for their accounts — must be prevented from using Amazon DynamoDB, while they retain access to other AWS services. Which method will enforce this restriction organization-wide?
Choose an answer
Tap an option to check your answer.
Correct answer: From the management account create a Service Control Policy (SCP) that denies all DynamoDB actions and attach it to the organization root..
Why this is the answer
Creating a Service Control Policy (SCP) in the management account and attaching it to the organization root is the most effective way to enforce a restriction across all member accounts, including the root user. SCPs apply to all users and roles in affected accounts, including the root user, and cannot be overridden by IAM policies within those accounts. Attaching IAM policies in every member account is impractical for a large organization and can be bypassed by the root user. Denying managed policies is insufficient as users could still gain access through inline policies or other managed policies. Replacing the default SCP is unnecessary; you can add new SCPs alongside existing ones.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed