Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 156 Topic 16 Discussion

Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 156 Topic 16 Discussion

SAA-C03 Exam Topic 16 Question 156 Discussion:
Question #: 156
Topic #: 16

A global company operates in multiple AWS Regions to meet data residency requirements. The company uses AWS Organizations to manage its accounts. The company wants to restrict IAM roles and access to specific Regions to prevent accidental data operations across geographic boundaries.

Which solution will meet these requirements?


A.

Configure a service control policy (SCP) to deny the ec2:RunInstances action in non-compliant Regions.


B.

Configure IAM policies by using the aws:RequestedRegion condition.


C.

Configure IAM role trust policies that use the aws:SourceIp condition.


D.

Configure AWS Config to detect unwanted access across Regions.


Get Premium SAA-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.