Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 45 Topic 5 Discussion

Amazon Web Services AWS Certified Security - Specialty SCS-C02 Question # 45 Topic 5 Discussion

SCS-C02 Exam Topic 5 Question 45 Discussion:
Question #: 45
Topic #: 5

A company deploys a set of standard IAM roles in AWS accounts. The IAM roles are based on job functions within the company. To balance operational efficiency and security, a security engineer implemented AWS Organizations SCPs to restrict access to critical security services in all company accounts.

All of the company's accounts and OUs within AWS Organizations have a default FullAWSAccess SCP that is attached. The security engineer needs to ensure that no one can disable Amazon GuardDuty and AWS Security Hub. The security engineer also must not override other permissions that are granted by IAM policies that are defined in the accounts.

Which SCP should the security engineer attach to the root of the organization to meet these requirements?


A.

B.

B. A screenshot of a computer code Description automatically generated


C.

A screenshot of a computer code Description automatically generated


D.

A screenshot of a computer code Description automatically generated


Get Premium SCS-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.