MediaFlux has a Control Tower landing zone. The security team must prevent resource creation outside us-east-1 and us-west-2 and must block any public read access to S3 buckets across all enrolled accounts. Which guardrails should they enable? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Enable the Control Tower preventive guardrail that disallows actions in non-approved Regions., Enable the Control Tower preventive guardrail that disallows public read access to S3 buckets..
Why this is the answer
The correct options are preventive guardrails because the requirement is to prevent resource creation and public read access, not just detect it. Preventive guardrails use Service Control Policies (SCPs) to enforce restrictions at the organizational level, ensuring compliance before resources are provisioned or configurations are made. "Enable the Control Tower preventive guardrail that disallows actions in non-approved Regions" directly addresses the need to prevent resource creation outside us-east-1 and us-west-2. "Enable the Control Tower preventive guardrail that disallows public read access to S3 buckets" directly addresses the need to block public read access to S3 buckets. The detective guardrails are incorrect because they only detect violations after they occur, rather than preventing them, which is the explicit requirement. Configuring account-level S3 Block Public Access via a lifecycle action is not a standard Control Tower guardrail and would be a manual or custom automation step, not a built-in guardrail.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed