New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 19 Topic 2 Discussion

Amazon Web Services AWS Certified Security – Specialty SCS-C03 Question # 19 Topic 2 Discussion

SCS-C03 Exam Topic 2 Question 19 Discussion:
Question #: 19
Topic #: 2

A company is running a new workload across accounts in an organization in AWS Organizations. All running resources must have a tag of CostCenter, and the tag must have one of three approved values. The company must enforce this policy and must prevent any changes of the CostCenter tag to a non-approved value.

Which solution will meet these requirements?


A.

Use AWS Config custom policy rule and an SCP to deny non-approved aws:RequestTag/CostCenter values.


B.

Use CloudTrail + EventBridge + Lambda to block creation.


C.

Enable tag policies, define allowed values, enforce noncompliant operations, and use an SCP to deny creation when aws:RequestTag/CostCenter is null.


D.

Enable tag policies and use EventBridge + Lambda to block changes.


Get Premium SCS-C03 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.