AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question

A compliance mandate requires that no member account in the company's AWS Organization can provision resources outside the us-east-1 or us-west-2 Regions and that Amazon Redshift is completely blocked. The CloudOps team needs a centrally managed, preventive control that applies to existing and future accounts without modifying individual IAM roles. Which solution meets these requirements?

  • Deploy AWS Control Tower and enable guardrails to disable unsupported Regions and block the Redshift service across the organization.

  • Create an IAM permission boundary in each account that allows only approved Regions and excludes Redshift actions, then attach it to every user and role.

  • Attach a Service Control Policy to the organization root that denies all actions when aws:RequestedRegion is anything other than us-east-1 or us-west-2 and denies redshift:* for all principals.

  • Enable an AWS Config rule that detects resources created in unauthorized Regions or any Redshift cluster and invokes Systems Manager Automation to delete them.

AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot