Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 118 Topic 12 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 118 Topic 12 Discussion

SCS-C02 Exam Topic 12 Question 118 Discussion:
Question #: 118
Topic #: 12

A company has an organization in AWS Organizations. The organization consists of multiple OUs. The company must prevent 1AM principals from outside the organization from accessing the organization's Amazon S3 buckets. The solution must not affect the existing access that the OUs have to the S3 buckets.

Which solution will meet these requirements?


A.

Configure S3 Block Public Access for all S3 buckets.


B.

Configure S3 Block Public Access for all AWS accounts.


C.

Deploy an SCP that includes the "awsiResourceOrgPaths": "${aws:PrincipalOrgPaths}" condition.


D.

Deploy an SCP that includes the "aws:ResourceOrglD": "${aws:PrincipalOrglD}" condition.


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.