AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A financial-services company uses AWS Organizations. Developers in several member accounts create and update application secrets in AWS Secrets Manager only in the us-east-1 Region. Because of regulatory restrictions, no secret may be replicated to any other AWS Region-either when the secret is first created or later in its lifecycle. The security team wants a preventive control that:

  • still lets developers perform all other Secrets Manager operations in us-east-1, and
  • imposes the least ongoing operational overhead across the organization.

Which solution meets these requirements?

  • Attach an organization-wide service control policy that denies Secrets Manager actions whenever the request includes the AddReplicaRegions parameter, using a condition such as "Null":{"secretsmanager:AddReplicaRegions":"false"}. All other Secrets Manager actions are allowed.

  • Remove the secretsmanager:ReplicateSecretToRegions permission from every developer IAM role in each member account but leave all other Secrets Manager permissions intact.

  • Configure customer-managed AWS KMS keys that are usable only in us-east-1 and require Secrets Manager to encrypt every secret with those keys so that attempts to replicate the secret in other Regions fail.

  • Create an AWS Config custom rule that detects calls to ReplicateSecretToRegions or CreateSecret with AddReplicaRegions, and trigger an AWS Lambda function to delete any replica secret that is found.

AWS Certified Solutions Architect Professional SAP-C02
Continuous Improvement for Existing Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot