AWS Certified Solutions Architect – Associate (SAA-C03)Design Secure ArchitecturesMedium
A large enterprise uses AWS Organizations to manage multiple AWS accounts. They want to ensure that all AWS accounts within their organization adhere to a strict security policy that prohibits the creation of Amazon S3 buckets that are publicly accessible. This policy must be enforced at the organizational level and prevent any account from overriding it. Which AWS service should be used to implement this control?
- AService Control Policies (SCPs)
- BAWS WAF
- CIAM Policies
- DResource-based Policies
Show answer & explanationAnswer & explanation
Correct answer: A. Service Control Policies (SCPs)
Service Control Policies (SCPs) are a feature of AWS Organizations that allow you to manage permissions in your organization. SCPs can be used to set maximum available permissions for all accounts in an organization or for individual OUs. They are preventive controls that restrict actions, ensuring no account can override them, which directly addresses the requirement.
Why the other options are wrong
- B. AWS WAF is a web application firewall that protects web applications from common web exploits; it does not control S3 bucket public access at the organizational level.
- C. IAM Policies are applied to IAM users, groups, or roles within a single account and can be overridden or bypassed at the organizational level.
- D. Resource-based Policies (like S3 bucket policies) are attached to specific resources and apply only to those resources within an account, not across the entire organization as a preventive control.
AWS Organizations SCPs
Service Control Policies (SCPs) are a type of policy that you can use to manage permissions in your organization in AWS Organizations.
- Act as guardrails, setting maximum available permissions.
- Applied to the root, Organizational Units (OUs), or individual accounts.
- Preventive controls that cannot be overridden by IAM policies.
Memory trick: SCPs are the security 'S'uper 'C'ontrol 'P'ower for your organization.