Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified DevOps Engineer - Professional DOP-C02 Question # 50 Topic 6 Discussion

Amazon Web Services AWS Certified DevOps Engineer - Professional DOP-C02 Question # 50 Topic 6 Discussion

DOP-C02 Exam Topic 6 Question 50 Discussion:
Question #: 50
Topic #: 6

A company uses AWS Organizations, AWS Control Tower, AWS Config, and Terraform to manage its AWS accounts and resources. The company must ensure that users deploy only AWS Lambda functions that are connected to a VPC in member AWS accounts.

Which solution will meet these requirements with the LEAST operational effort?


A.

Configure AWS Control Tower to use proactive controls (guardrails). Enable optional controls implemented with AWS CloudFormation hooks for Lambda on all OUs.


B.

Create a new SCP that checks the lambda:VpcIds condition key for allowed values.


C.

Create a custom AWS Config rule to detect non-VPC-connected Lambda functions.


D.

Create a new SCP with a conditional statement that denies Lambda creation if lambda:VpcIds is null.


Get Premium DOP-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.