ExamQuestions.com

Register
Login
AWS Certified SysOps Administrator Associate Exam Questions

Amazon

AWS Certified SysOps Administrator Associate

95 / 340

Question 95:

A global pharma company has provided access to external vendors of the documents stored in the Amazon S3 bucket owned by an R & D account within the AWS Organizations. All accesses to the bucket need to be immediately removed as the vendors are no longer affiliated with the company. As a SysOps administrator, you applied SCP at the OU level to which the R&D account is part, denying all access to the Amazon S3 bucket. Based on AWS CloudTrail Logs external vendors can still access the S3 bucket.
What could be possible reasons for users still have access to the Amazon S3 bucket?

Answer options:

A.SCP does not apply to users outside the AWS Organizations.
B.SCP needs to be applied at account level instead of OU level.
C.SCP needs to be applied at root level instead of OU level.
D.IAM Policy needs to be created for users to explicitly deny access to Amazon S3 bucket along with SCP.