For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 5Question 02
    Medium1 markMultiple Choice
    Domain 1.2: Security ControlsSecurityOrganizationsSCP

    AWS SAP-C02 · Question 02 · Domain 1.2: Security Controls

    A company uses AWS Organizations to manage multiple accounts. The security team mandates that no Amazon S3 buckets can be made public, and all EBS volumes must be encrypted. Developers need the ability to manage their own IAM roles, but must not be able to bypass these security controls. Which combination of actions should the Solutions Architect take? (Select TWO)

    Answer options:

    A.

    Create a Service Control Policy (SCP) that denies the s3:PutBucketPublicAccessBlock action and attach it to the root of the organization.

    B.

    Create an SCP that denies the ec2:CreateVolume action if the encrypted flag is false and attach it to the root.

    C.

    Use AWS IAM permissions boundaries on all developer roles to deny S3 public access and enforce EBS encryption.

    D.

    Enable AWS Config rules in the management account to automatically terminate unencrypted EBS volumes.

    E.

    Create an IAM policy denying S3 public access and attach it to the AWS Organizations management account.

    F.

    Use AWS CloudTrail to monitor for unencrypted volumes and trigger a Lambda function to encrypt them.

    How to approach this question

    Look for preventive controls that apply organization-wide and cannot be bypassed by local account administrators.

    Full Answer

    SCPs offer central control over the maximum available permissions for all accounts in your organization. They ensure your accounts stay within your organization's access control guidelines.

    Common mistakes

    Choosing IAM policies or boundaries, which can be bypassed if developers have IAM creation permissions.
    Question 01All questionsQuestion 03

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 5

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is redesigning its AWS network architecture across 50 AWS accounts and 3 AWS ...HardQ03A financial institution requires a disaster recovery strategy for its critical trading applicatio...HardQ04An enterprise is setting up a new multi-account AWS environment using AWS Control Tower. They nee...MediumQ05A company has a complex AWS environment with hundreds of linked accounts under AWS Organizations....HardQ06An architecture team is designing a hybrid network. They have two on-premises data centers and th...Hard
    View all 75 questions →