Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 143 Topic 15 Discussion

Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 143 Topic 15 Discussion

SAA-C03 Exam Topic 15 Question 143 Discussion:
Question #: 143
Topic #: 15

A development team uses multiple AWS accounts for its development, staging, and production environments. Team members have been launching large Amazon EC2 instances that are underutilized. A solutions architect must prevent large instances from being launched in all accounts.

How can the solutions architect meet this requirement with the LEAST operational overhead?


A.

Update the IAM policies to deny the launch of large EC2 instances. Apply the policies to all users.


B.

Define a resource in AWS Resource Access Manager that prevents the launch of large EC2 instances.


C.

Create an (AM role in each account that denies the launch of large EC2 instances. Grant the developers IAM group access to the role.


D.

Create an organization in AWS Organizations in the management account with the default policy. Create a service control policy (SCP) that denies the launch of large EC2 Instances, and apply it to the AWS accounts.


Get Premium SAA-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.