New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon SCS-C02 Exam - Topic 9 Question 2 Discussion

Actual exam question for Amazon's SCS-C02 exam
Question #: 2
Topic #: 9
[All SCS-C02 Questions]

A company is expanding its group of stores. On the day that each new store opens, the company wants to launch a customized web application for that store. Each store's application will have a non-production environment and a production environment. Each environment will be deployed in a separate AWS account. The company uses AWS Organizations and has an OU that is used only for these accounts.

The company distributes most of the development work to third-party development teams. A security engineer needs to ensure that each team follows the company's

deployment plan for AWS resources. The security engineer also must limit access to the deployment plan to only the developers who need access. The security engineer already has created an AWS CloudFormation template that implements the deployment plan.

What should the security engineer do next to meet the requirements in the MOST secure way?

Show Suggested Answer Hide Answer
Suggested Answer: A

The correct answer is A. Create an AWS Service Catalog portfolio in the organization's management account. Upload the CloudFormation template. Add the template to the portfolio's product list. Share the portfolio with the OU.

According to the AWS documentation, AWS Service Catalog is a service that allows you to create and manage catalogs of IT services that are approved for use on AWS. You can use Service Catalog to centrally manage commonly deployed IT services and help achieve consistent governance and compliance requirements, while enabling users to quickly deploy only the approved IT services they need.

To use Service Catalog with multiple AWS accounts, you need to enable AWS Organizations with all features enabled. This allows you to centrally manage your accounts and apply policies across your organization. You can also use Service Catalog as a service principal for AWS Organizations, which lets you share your portfolios with organizational units (OUs) or accounts in your organization.

To create a Service Catalog portfolio, you need to use an administrator account, such as the organization's management account. You can upload your CloudFormation template as a product in your portfolio, and define constraints and tags for it. You can then share your portfolio with the OU that contains the accounts for the web applications. This will allow the developers in those accounts to launch products from the shared portfolio using the Service Catalog end user console.

Option B is incorrect because CloudFormation modules are reusable components that encapsulate one or more resources and their configurations. They are not meant to be used as templates for deploying entire stacks of resources. Moreover, sharing a module with an OU does not grant access to launch stacks from it.

Option C is incorrect because creating an IAM role that has a trust policy that allows cross-account access to the portfolio is not secure. It would allow any user in the OU accounts to assume the role and access the portfolio, regardless of their job function or access requirements.

Option D is incorrect because sharing a module with an OU does not grant access to launch stacks from it. It also does not limit access to the deployment plan to only the developers who need access.


Contribute your Thoughts:

0/2000 characters
Sang
3 months ago
Isn't it a bit overkill to create a module for a simple template?
upvoted 0 times
...
Cassandra
3 months ago
I agree, option C seems like the safest route for cross-account access.
upvoted 0 times
...
Lauran
4 months ago
Wait, can we really limit access that tightly with just IAM roles?
upvoted 0 times
...
Jody
4 months ago
I think option B is better for security though.
upvoted 0 times
...
Clement
4 months ago
Sounds like a solid plan with AWS Service Catalog!
upvoted 0 times
...
Gladys
4 months ago
I think using the CloudFormation CLI to create a module could be a good approach, but I’m not entirely confident about the SCP part.
upvoted 0 times
...
Viola
4 months ago
I’m a bit confused about the difference between the Service Catalog and the CloudFormation CLI options. Which one is more secure?
upvoted 0 times
...
Ilene
5 months ago
This question feels similar to the practice exam where we had to manage access to resources. I think creating an IAM role might be key.
upvoted 0 times
...
Meghan
5 months ago
I remember we discussed AWS Service Catalog in class, but I'm not sure if it’s the best option here.
upvoted 0 times
...
Chanel
5 months ago
I feel confident about this one. The security requirements are clear, and I think I can identify the best solution based on the information provided.
upvoted 0 times
...
Ivan
5 months ago
This is a tricky one. I'm a bit confused about the differences between the AWS Service Catalog and the CloudFormation registry options. I'll need to read through the details carefully.
upvoted 0 times
...
Levi
5 months ago
Okay, I think I've got this. The question is asking for the most secure approach, so I'll focus on the options that prioritize security and access control.
upvoted 0 times
...
Cordell
5 months ago
This question seems straightforward, but I want to make sure I understand the requirements correctly before I start.
upvoted 0 times
...
Chandra
5 months ago
Hmm, the key here is to find the most secure way to limit access to the deployment plan. I think I have a good strategy in mind, but I'll double-check the options to make sure I'm not missing anything.
upvoted 0 times
...
Frederica
5 months ago
I'm a bit confused by this question. Should the Scrum Master involve the whole team or just use coaching techniques? I'm not sure which two techniques are the best approach.
upvoted 0 times
...
Jesusita
5 months ago
Okay, let me take a closer look at the exhibit. I think I can figure this out if I focus on the key information provided.
upvoted 0 times
...

Save Cancel