AWS Certified Security – SpecialtyDomain 5: Data ProtectionMedium

A financial institution is migrating its on-premises data to AWS. Due to strict regulatory requirements, they need to prevent any AWS account within their organization from creating S3 buckets in regions outside of the EU (e.g., US regions) to ensure data residency. They also need to enforce that all S3 buckets are created with default encryption enabled. Which AWS service can enforce these organization-wide policies?

  1. AAWS CloudFormation Guard rules to validate templates before deployment.
  2. BAmazon S3 bucket policies applied to each S3 bucket.
  3. CAWS Service Control Policies (SCPs) applied to Organizational Units (OUs) or the root of the organization.
  4. DAWS Identity and Access Management (IAM) policies applied to individual users and roles.
Show answer & explanation

Correct answer: C. AWS Service Control Policies (SCPs) applied to Organizational Units (OUs) or the root of the organization.

AWS Service Control Policies (SCPs) are designed to enforce permissions across all accounts in an AWS Organization. They can be used to deny actions like 's3:CreateBucket' if the request specifies a region outside the EU and to deny 's3:PutBucketEncryption' if default encryption is not enabled, thereby enforcing organization-wide data residency and encryption policies.

Why the other options are wrong

  • A. CloudFormation Guard is for policy-as-code validation during deployment, but SCPs provide runtime enforcement across all AWS resources, regardless of deployment method.
  • B. S3 bucket policies are applied to specific S3 buckets, not across all accounts or for preventing bucket creation in certain regions.
  • D. IAM policies are for individual accounts, users, or roles, not organization-wide enforcement across multiple accounts.

AWS Service Control Policies (SCPs)

Policies that provide central control over the maximum available permissions for all accounts in an AWS Organization, allowing organizations to enforce compliance and security standards across all member accounts.

  • Apply to OUs or the organization root, affecting all child accounts.
  • Can be used to whitelist or blacklist AWS services and actions.
  • Do not grant permissions; they filter permissions granted by IAM policies.

Memory trick: SCPs are the organizational cops, keeping everyone in line.

More Domain 5: Data Protection questions