If you remove the FullAWSAccess policy from the Development OU and attach a policy that allows all actions on EC2 resources, what is the resulting effective permission for users in the Development OU?
Choose an answer
Tap an option to check your answer.
Correct answer: All users in the Development OU will be allowed all API actions on EC2 resources; all other API actions will be denied..
Why this is the answer
AWS Organizations Service Control Policies (SCPs) define the maximum available permissions for accounts within an Organizational Unit (OU). When you remove the FullAWSAccess policy, you remove the broad "allow all" permission. Attaching a new SCP that specifically allows all actions on EC2 resources means that users in the Development OU can perform any action on EC2. For any other AWS service or resource type not explicitly allowed by an SCP, the default behavior is an implicit deny. Therefore, while EC2 actions are permitted, all other API actions will be denied because no SCP grants permission for them.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed