AWS Certified Solutions Architect Associate SAA-C03 Practice Question
Your company needs to centrally manage access policies across multiple organizational units within their cloud environment. Which service offered by Amazon Web Services should they use to achieve this?
AWS Organizations enables you to centrally govern and manage your environment as you grow and scale your workloads on AWS. It allows you to group accounts into Organizational Units (OU), and apply Service Control Policies (SCPs) to manage services and permissions for those OUs. AWS Identity and Access Management (IAM) helps you securely control access to services and resources within a single account, not across multiple accounts. Amazon Cognito provides user authentication, authorization and management for web and mobile apps, hence, irrelevant for managing multiple AWS accounts. AWS CloudTrail tracks user activity and API usage for auditing purposes but does not manage access policies across organizational units.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Service Control Policies (SCPs)?
Open an interactive chat with Bash
How does AWS Organizations help in managing multiple accounts?
Open an interactive chat with Bash
What is the difference between AWS Organizations and IAM?