AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A financial-services company with an AWS Organizations hierarchy must prevent creation of any resources outside us-east-1 and us-east-2 to meet regulatory requirements. The CloudOps team wants a solution that blocks non-compliant API calls across all existing and future member accounts with the least ongoing operational effort. Which approach satisfies these requirements?
Create an IAM permission boundary in every account that allows actions only in the approved Regions and mandate its use for all roles.
Deploy the AWS Config managed rule that detects resources in unapproved Regions and use Systems Manager Automation to delete any that are found.
Enable a multi-Region CloudTrail and configure Amazon EventBridge to invoke a Lambda function that stops or deletes resources launched in other Regions.
Attach a service control policy at the organization root that denies all actions when the aws:RequestedRegion condition is not us-east-1 or us-east-2.
A service control policy (SCP) applied to the organization root is evaluated before IAM permissions in every member account. By using a Deny statement with the aws:RequestedRegion condition key, the SCP blocks any API call targeting a Region other than us-east-1 or us-east-2, preventing resource creation proactively in both existing and newly added accounts without additional setup.
Permission boundaries must be attached to every principal in every account and do not automatically cover new accounts, increasing operational overhead. An AWS Config rule or an EventBridge-triggered Lambda provide only detective or reactive controls-they allow the non-compliant resource to be created before remediation and require additional automation to remain effective. Therefore, the SCP is the simplest and most effective preventive control for Region enforcement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Service Control Policy (SCP) in AWS Organizations?
Open an interactive chat with Bash
How does the **aws:RequestedRegion** condition key work in SCPs?
Open an interactive chat with Bash
Why are SCPs a better choice than IAM permission boundaries for Region enforcement?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .