Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 6 Topic 1 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 6 Topic 1 Discussion

SCS-C02 Exam Topic 1 Question 6 Discussion:
Question #: 6
Topic #: 1

A company has an organization with SCPs in AWS Organizations. The root SCP for the organization is as follows:

SCS-C02 Question 6

The company's developers are members of a group that has an IAM policy that allows access to Amazon Simple Email Service (Amazon SES) by allowing ses:* actions. The account is a child to an OU that has an SCP that allows Amazon SES. The developers are receiving a not-authorized error when they try to access Amazon SES through the AWS Management Console.

Which change must a security engineer implement so that the developers can access Amazon SES?


A.

Add a resource policy that allows each member of the group to access Amazon SES.


B.

Add a resource policy that allows "Principal": {"AWS": "arn:aws:iam::account-number:group/Dev"}.


C.

Remove the AWS Control Tower control (guardrail) that restricts access to Amazon SES.


D.

Remove Amazon SES from the root SCP.


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.