Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 18 Topic 2 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 18 Topic 2 Discussion

SCS-C02 Exam Topic 2 Question 18 Discussion:
Question #: 18
Topic #: 2

A security administrator is restricting the capabilities of company root user accounts. The company uses AWS Organizations and has all features enabled. The management account is used for billing and administrative purposes, but it is not used for operational AWS resource purposes.

How can the security administrator restrict usage of member root user accounts across the organization?


A.

Disable the use of the root user account at the organizational root. Enable multi-factor authentication (MFA) of the root user account for each organization member account.


B.

Configure 1AM user policies to restrict root account capabilities for each organization member account.


C.

Create an OU in Organizations, and attach an SCP that controls usage of the root user. Add all member accounts to the new OU.


D.

Configure AWS CloudTrail to integrate with Amazon CloudWatch Logs Create a metric filter for RootAccountUsage.


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.