The company changed corporate network IP ranges. Ten S3 buckets across different accounts restrict access to the private corporate network range. Two organizational units (OUs) must have their access revoked. How should you update the buckets and revoke access for the two OUs?
Choose an answer
Tap an option to check your answer.
Correct answer: Update each S3 bucket’s resource-based policy to allow only the new IP range and create a new SCP that denies access to the S3 buckets. Attach that SCP to the two OUs..
Why this is the answer
The correct approach involves two steps: updating S3 bucket policies and using Service Control Policies (SCPs). First, updating each S3 bucket's resource-based policy to allow only the new IP range ensures that access from outdated IP ranges is immediately blocked at the bucket level. Second, creating an SCP to deny access to these S3 buckets and attaching it to the two OUs provides a centralized and effective way to revoke access for all accounts within those OUs, overriding any individual IAM policies. The incorrect options either miss a crucial step or use less effective methods. Simply updating resource-based policies without an SCP for OUs doesn't centrally revoke access. Using only SCPs for IP range restriction is less granular than bucket policies. Permissions boundaries on OrganizationAccountAccessRole are for controlling what permissions can be delegated, not for directly denying access to specific resources across an OU.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed