AWS Certified Solutions Architect Professional SAP-C02 Practice Question

Your company has an AWS Organization with a Dev OU that contains more than 50 sandbox accounts. Project leads in those accounts must be able to create and manage IAM roles for their micro-services. Security has mandated that any new role must never obtain permissions outside Amazon S3 and Amazon DynamoDB, and this guardrail must apply automatically to future roles without requiring manual review. The solution must impose the least ongoing operational effort while still letting project leads create and update their own roles.

Which approach meets these requirements?

  • Attach an SCP to the Dev OU that allows only S3 and DynamoDB service actions for every principal in the member accounts, then permit project leads to create roles without additional controls.

  • Enable IAM Access Analyzer in each account and invoke an AWS Lambda function through EventBridge to delete any role whose policy includes actions outside S3 and DynamoDB.

  • Require all role creation requests to pass through a central AWS CloudFormation pipeline that is manually reviewed and approved by the security team before deployment.

  • Create a customer-managed policy that permits only Amazon S3 and DynamoDB actions, designate it as a permissions boundary, and apply an Organizations SCP to the Dev OU that denies iam:CreateRole unless that permissions boundary is specified.

AWS Certified Solutions Architect Professional SAP-C02
Design for New Solutions
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot