An account less than one year old is in an AWS Organizations OU. The company wants an Organizations structure and an SCP that allow only services currently used in that account. IAM Access Analyzer will be used to determine active services. What steps will achieve this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an SCP that allows only the services identified by IAM Access Analyzer. Create a new OU, move the account into it, attach the new SCP to the OU, and detach the default FullAWSAccess SCP from that OU..
Why this is the answer
This option correctly outlines the steps for implementing a restrictive SCP based on active services. Creating an SCP that allows only the identified services ensures a "least privilege" approach. Placing the account in a new OU and attaching the SCP to that OU provides granular control, affecting only the target account. Detaching the FullAWSAccess SCP is crucial because SCPs are evaluated in a hierarchical manner, and FullAWSAccess would override any restrictive SCPs if left attached. The option to "deny" services would be less effective and harder to manage, as new services would be implicitly allowed unless explicitly denied. Attaching the SCP to the organization root would affect all accounts, which is not the desired scope. Attaching the SCP to the management account would not apply it to the target account within the OU.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed