AWS Certified Solutions Architect – ProfessionalContinuously Improve Existing SolutionsHard

A global enterprise uses AWS Organizations to manage multiple AWS accounts. They need to enforce strict compliance and security policies across all accounts, including preventing users from launching EC2 instances in unsupported regions and ensuring that all S3 buckets are encrypted by default. These policies must be applied consistently to newly created accounts and existing ones, without exceptions. Which AWS service should the Solutions Architect recommend to implement these guardrails?

  1. AResource-based policies applied to specific AWS resources like S3 buckets and EC2 instances.
  2. BService Control Policies (SCPs) within AWS Organizations.
  3. CAWS Identity and Access Management (IAM) policies applied to individual users and roles.
  4. DAWS Config rules deployed in each account to monitor for non-compliant resources.
Show answer & explanation

Correct answer: B. Service Control Policies (SCPs) within AWS Organizations.

Service Control Policies (SCPs) in AWS Organizations enable central control over the maximum available permissions for all accounts in an organization. They can be used to prevent actions like launching resources in specific regions or creating unencrypted S3 buckets, ensuring strict compliance across all accounts, including new ones, with no exceptions.

Why the other options are wrong

  • A. Resource-based policies are attached to individual resources and define who can access that specific resource. They are not suitable for enforcing broad, preventative, organization-wide policies across all accounts and resource types.
  • C. IAM policies define permissions for users and roles within a single account. While powerful, they cannot restrict the root user, are cumbersome to manage across many accounts, and don't prevent new accounts from being created without these policies.
  • D. AWS Config rules are detective controls; they monitor for non-compliant resources after they have been created and then report on them. They do not prevent actions from happening in the first place, which is required for 'preventing users from launching' and 'ensuring' policies 'without exceptions'.

Service Control Policies (SCPs)

Service Control Policies (SCPs) are a type of organization policy that you can use to manage permissions in your organization. SCPs offer central control over the maximum available permissions for all accounts in your organization.

  • Preventative guardrails that deny actions.
  • Apply to all IAM users and roles, including the root user.
  • Applied at the OU or root level and inherited by child accounts.

Memory trick: SCPs Secure Strict Standards.

More Continuously Improve Existing Solutions questions