AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
Your company manages about 80 AWS accounts that are organized under a single AWS Organizations hierarchy. Until a pending security review is finished, the compliance team forbids the use of Amazon MQ in any account, but developers must continue using all other approved services without interruption. The CloudOps team needs a centrally managed, preventative control that applies automatically to new and existing accounts with minimal ongoing maintenance. Which solution meets these requirements MOST effectively?
Attach a service control policy to the organization (or OU) that explicitly denies all mq:* actions for every principal.
Require every IAM role in all accounts to use a permission boundary that excludes mq:* actions.
Enable a CloudTrail trail in each account and use an EventBridge rule to trigger a Lambda function that deletes any newly created Amazon MQ resources.
Create an organization-wide AWS Config rule that flags the creation of Amazon MQ brokers as non-compliant.
Service control policies (SCPs) are organization-wide guardrails that specify the maximum permissions an account can use. Attaching an SCP that denies all mq:* actions to the organization or the relevant OU prevents every principal in each member account-now and in the future-from creating or modifying Amazon MQ resources. AWS Config rules only detect non-compliance and cannot block API calls. A CloudTrail-based Lambda remediation is reactive, incurs extra cost, and allows non-compliant resources to exist briefly. IAM permission boundaries would have to be attached to every role in every account and kept in sync, creating significant operational overhead and still not covering unmanaged identities such as the root user. Therefore, an SCP is the most effective preventive control for enforcing this service-selection compliance requirement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Service Control Policy (SCP) in AWS Organizations?
Open an interactive chat with Bash
How do SCPs differ from IAM policies?
Open an interactive chat with Bash
Why are SCPs more effective than AWS Config rules or Lambda for this scenario?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .