The company wants to block developers from launching a specific EC2 instance family across multiple AWS accounts that are managed with AWS Organizations. What is the most operationally efficient way to apply the service control policy restriction to all those accounts?
Choose an answer
Tap an option to check your answer.
Correct answer: Add the accounts to an organizational unit (OU). Apply the SCPs to the OU..
Why this is the answer
Applying Service Control Policies (SCPs) to an Organizational Unit (OU) is the most operationally efficient method. SCPs inherited by accounts within an OU ensure consistent enforcement across multiple accounts with a single policy attachment. This centralizes management and reduces administrative overhead. Applying SCPs to individual developer accounts would be time-consuming and prone to errors, especially with a large number of accounts. AWS Resource Groups are for organizing resources, not for applying SCPs to accounts. AWS Control Tower automates landing zone setup but SCPs are still managed through AWS Organizations, typically by applying them to OUs.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed