Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 21 Topic 3 Discussion

Amazon Web Services AWS Certified Solutions Architect - Associate (SAA-C03) SAA-C03 Question # 21 Topic 3 Discussion

SAA-C03 Exam Topic 3 Question 21 Discussion:
Question #: 21
Topic #: 3

A company uses AWS CloudFormation to deploy IAM resources within accounts that AWS Control Tower governs. The security team wants to prevent the deployment of IAM roles that include inline policies with the following statements:

" Effect " : " Allow " , " Action " : " * " , " Resource " : " * "

Which solution will meet this requirement?


A.

Use AWS Control Tower proactive controls to block CloudFormation stacks that match these inline policy statements.


B.

Use AWS Control Tower detective controls to detect and delete IAM inline policies that contain these statements upon deployment.


C.

Use AWS Config to create a rule that detects these statements in any inline IAM policies. Configure the rule to automatically remove these statements by using the AWS-DeleteIAMInlinePolicy remediation.


D.

Use AWS Config to create a rule that detects these statements in inline IAM policies and sends a notification to the security team.


Get Premium SAA-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.