Question 1 of 30
AstroDynamics, a global technology firm, is migrating its sensitive customer data processing workloads to AWS. The company operates under stringent data residency regulations in several jurisdictions, requiring that Personally Identifiable Information (PII) originating from specific customer bases must remain within designated AWS Regions. As part of a broader disaster recovery initiative, they are planning to implement multi-region architectures. The challenge is to establish a proactive and auditable framework that prevents the accidental or intentional deployment of resources that could violate these data residency laws, ensuring that all data storage and processing adheres to geographical compliance mandates across all their AWS accounts. Which architectural approach would most effectively satisfy these requirements for granular, cross-account enforcement of data residency policies?
Implement AWS Organizations Service Control Policies (SCPs) to deny resource creation in prohibited AWS Regions, coupled with AWS Config rules to continuously monitor and audit resource configurations against data residency mandates.
Utilize AWS Lambda functions triggered by AWS CloudTrail to detect and terminate non-compliant resources, and employ S3 bucket policies with strict replication controls for data at rest.
Configure AWS Identity and Access Management (IAM) policies at the account level to restrict access to specific AWS Regions, and leverage Amazon Macie for data discovery and classification to identify PII.
Deploy AWS Global Accelerator to route traffic to compliant regions only, and use Amazon GuardDuty to alert on suspicious cross-region data access patterns.

Preparing for AWS Certified Solutions Architect Professional SAPC02 AWS Certified Solutions Architect Professional SAPC02? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free