AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
An enterprise uses AWS Organizations with a single root and two organizational units (OUs) named Prod and Dev. The security team must guarantee that Dev accounts cannot launch Amazon EC2 instances that receive a public IPv4 address, while Prod accounts retain full functionality. The solution must be centrally enforced and impossible for Dev account administrators to bypass. Which approach meets these requirements MOST effectively?
Attach an SCP to the Dev OU that explicitly denies ec2:RunInstances when the request parameter AssociatePublicIpAddress is true.
Enable Amazon GuardDuty in the management account and configure an organization-wide detector to block Dev accounts from launching instances with public IP addresses.
In every Dev account, attach an IAM customer managed policy that denies launching EC2 instances with public IP addresses to all users and roles.
Enable AWS Config across the organization and add a rule that terminates any instance in the Dev OU that is launched with a public IP address.
A service control policy (SCP) attached to the Dev OU establishes an organization-wide guardrail. By adding an explicit Deny on ec2:RunInstances when the request includes the parameter "AssociatePublicIpAddress" set to true, no principal in any Dev account can grant itself permission to launch instances with public IPs. Because SCPs are evaluated before IAM policies and cannot be overridden by account administrators, the restriction is centrally enforced.
Creating IAM policies in each Dev account would work only until an administrator with sufficient privileges changes or detaches the policy. AWS Config and GuardDuty can detect or alert on non-compliant resources but cannot block the API call in real time, so they do not satisfy the requirement to prevent the action.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SCP in AWS?
Open an interactive chat with Bash
Why do SCPs take precedence over IAM policies in AWS Organizations?
Open an interactive chat with Bash
What are the limitations of IAM policies compared to SCPs?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .