An organization has multiple AWS accounts under AWS Organizations. Administrators have been using the root user credentials in member accounts, and the company wants to block any root-user actions on EC2 resources across all member accounts. What is the appropriate way for a SysOps administrator to enforce this requirement centrally?
Choose an answer
Tap an option to check your answer.
Correct answer: From the organization's management account, create a service control policy (SCP) that denies root-user actions on EC2 for all member accounts..
Why this is the answer
Creating a Service Control Policy (SCP) from the management account is the most appropriate and centralized way to enforce this requirement. SCPs allow you to set guardrails at the organizational level, restricting permissions for all member accounts, including the root user. This ensures consistent enforcement without needing to configure each account individually. Attaching identity-based IAM policies in each member account would be a manual, unscalable, and error-prone process. AWS Config is used for auditing and compliance, not for preventing actions. Amazon Inspector is a security vulnerability detection service and cannot block actions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed