An organization requires governance with these constraints: restrict resource access to the same two Regions for all accounts; limit allowed AWS services to a specific set; use Active Directory for authentication; and have identical job-function-based permissions in every account. Which solution meets these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a service control policy in the management account to restrict Regions and allowed services. Use AWS CloudFormation StackSets to provision roles for each job function, including an IAM trust policy for an external identity provider in each account..
Why this is the answer
The correct answer effectively addresses all requirements. A Service Control Policy (SCP) in the management account restricts Regions and allowed services across all accounts in the organization. AWS CloudFormation StackSets efficiently provision identical, job-function-based roles in every account. The IAM trust policy for an external identity provider (like Active Directory) enables authentication through the organization's existing directory. Incorrect options: Group policies are not an AWS service. Permission boundaries are applied to IAM principals (users/roles) within an account, not across an organization for region/service restrictions. AWS RAM shares resources, but not IAM roles in a way that allows cross-account assumption with an external IdP for job functions. IAM Identity Center (formerly AWS SSO) is an identity provider itself, not a mechanism to provision roles with trust policies to an external IdP.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed