Q: 7
A multinational company uses an organization in AWS Organizations to manage over 200 member
accounts across multiple AWS Regions. The company must ensure that all AWS resources meet
specific security requirements.
The company must not deploy any EC2 instances in the ap-southeast-2 Region. The company must
completely block root user actions in all member accounts. The company must prevent any user from
deleting AWS CloudTrail logs, including administrators. The company requires a centrally managed
solution that the company can automatically apply to all existing and future accounts. Which solution
will meet these requirements?
Options
Discussion
C imo, since only SCPs (with Control Tower) can actually deny both root actions and region usage org-wide. Nothing else here fully locks down root or enforces the org-level region deny. If someone sees a way D works, let me know.
C since SCPs with Control Tower are the only way to block root and restrict region at org level.
Its C. SCPs are the only way to restrict root user actions, D is tempting but Firewall Manager can't fully block root.
C/D? If "centrally managed" means it has to automatically apply to ALL *future* accounts too, does Firewall Manager cover that as easily as Control Tower? Or does the requirement include workload VPCs outside of the landing zone?
Be respectful. No spam.