Question 1 of 30
A company has multiple AWS accounts organized under an AWS Organization. They want to implement Service Control Policies (SCPs) to restrict certain actions across all accounts, particularly focusing on preventing the deletion of S3 buckets. The company has a policy that allows all actions except for the deletion of S3 buckets. However, they also have a specific account that requires the ability to delete S3 buckets for a particular application. How should the company structure their SCPs to achieve this requirement while ensuring that the general restriction remains in place for all other accounts?
Create a deny policy for S3 bucket deletion at the root level and an allow policy for the specific account that permits S3 bucket deletion.
Create an allow policy for S3 bucket deletion at the root level and a deny policy for the specific account.
Implement a deny policy for S3 bucket deletion at the organizational unit (OU) level and allow all actions for the specific account.
Establish a policy that allows S3 bucket deletion at the root level and denies all actions for the specific account.

Preparing for Amazon SAP-C02 AWS Certified Solutions Architect – Professional (SAP-C02)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free