A company's legacy application uses IAM user credentials to access resources in the company's AWS Organizations organization. A DevOps engineer needs to ensure new IAM users cannot be created unless the employee creating the IAM user is on an exception list. Which solution will meet these requirements?
A) Attach an Organizations SCP with an explicit deny for all iam:CreateAccessKey actions with a condition that excludes StringNotEquals for aws:username with a value of the exception list.
B) Attach an Organizations SCP with an explicit deny for all iam:CreateUser actions with a condition that includes StringEquals for aws:username with a value of the exception list.
C) Create an Amazon EventBridge (Amazon CloudWatch Events) rule with a pattern that matches the iam:CreateAccessKey action with an AWS Lambda function target. The function will check the user name account against an exception list. If the user is not in the exception list, the function will delete the user.
D) Create an Amazon EventBridge (Amazon CloudWatch Events) rule with a pattern that matches the iam:CreateUser action with an AWS Lambda function target. The function will check the user name and account against an exception list. If the user is not in the exception list, the function will delete the user.
Correct Answer:
Verified
Q489: You have an application which consists of
Q490: A Development team wants to deploy an
Q491: A company has multiple child accounts that
Q492: A company is deploying a container-based application
Q493: An application running on multiple Amazon EC2
Q495: A company has an application deployed using
Q496: You have decided that you need to
Q497: Which Auto Scaling process would be helpful
Q498: According to Information Security policy, changes to
Q499: A company updated the AWS CloudFormation template
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents