AWS Certified Solutions Architect Professional SAP-C02 Practice Question

Your company is migrating 300 on-premises servers to AWS. An AWS Control Tower landing zone with AWS Organizations is already in place.

A dedicated member account named Migration must be able to administer AWS Application Migration Service (AWS MGN) across every account while the organization's management account must remain locked down. To reduce the attack surface, the Migration account must be prevented from launching or modifying any AWS resources other than those required by AWS MGN.

Which approach meets all of these requirements with the least administrative effort?

  • Publish migration CloudFormation templates through AWS Service Catalog in the Migration account and deploy them to each workload account with StackSets; rely on the default FullAWSAccess SCP.

  • Configure AWS Application Migration Service only in the management account and use IAM permission boundaries to limit what migration users can do inside that account.

  • From the management account, enable trusted access for AWS Application Migration Service and register the Migration account as AWS MGN's delegated administrator. Attach an SCP to the Migration account that denies all actions except the AWS MGN APIs plus minimal read-only Organizations and STS permissions.

  • In every member account, create a cross-account IAM role that grants AWS ApplicationMigrationFullAccess and allow the Migration account to assume those roles. Do not configure delegated administrator or SCPs.

AWS Certified Solutions Architect Professional SAP-C02
Accelerate Workload Migration and Modernization
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot