makeporngreatagain.pro
yeahporn.top
hd xxx

Practice Test 1 | AWS Certified Cloud Practitioner | CLF-C01 | Dumps | Mock Test

23,813

AWS Organizations help manage multiple accounts effectively in a large enterprise. Which of the following statements related to AWS Organizations are correct? (Select TWO.)

A. An Organizational Unit(OU) can have only one parent.
B. An account can be a member of multiple Organizational Units (OU).
C. An SCP policy only impacts a particular AWS account even if it is applied at the root account.
D. Organizational level policies are known as Service Control Policies.
E. Service Control Policies (SCPs) can only allow actions instead of deny actions.

Answers: A, D

  • Option A is CORRECT.  An Organizational Unit(OU) can have a single branch going up, e.g. It can either inherit a root or another OU but not both as shown in the figure below.

  • Option B is incorrect since an Account can belong to only one OU.
  • Option C is incorrect. A Policy applied at the Root is applied throughout the Organization i.e. to all its OU’s and its Accounts. A Policy applied to the OU level applies to all OU’s and Accounts under those OU’s. A Policy applied at the Account level is applied to only that Account. Referring to the figure above, when a Policy is applied to the OU under the Root, it will also be applied to the OU below it & Accounts B, C, D. When a policy is applied to Account C, it will apply to only that account.
  • Option D is CORRECT. AWS Organizations automate creation of AWS Accounts, OUs and their hierarchy. They use Service Control Policies (SCP) at OUs. SCPs are different from IAM in the sense that they can be applied to the Organization level. They override any IAM policies that are defined at an Account level & may also restrict the IAM policy defined. AWS Organizations do not cancel the need for IAM. It compliments what IAM can do by consolidating and centrally managing a lot of things that happen. AWS Organizations is not an authority for granting permissions, but it is an authority to approve/disapprove permissions given by IAM.
  • Option E is incorrect. SCPs can be configured to allow or deny services and actions.

References:  

AWS Organizations user guide

Service Control Policies

Comments are closed, but trackbacks and pingbacks are open.

baseofporn.com https://www.opoptube.com
Ads Blocker Image Powered by Code Help Pro

Ads Blocker Detected!!!

We have detected that you are using extensions to block ads. Please support us by disabling these ads blocker.