Multiple Choice
A large global financial services company has multiple business units. The company wants to allow Developers to try new services, but there are multiple compliance requirements for different workloads. The Security team is concerned about the access strategy for on-premises and AWS implementations. They would like to enforce governance for AWS services used by business teams for regulatory workloads, including Payment Card Industry (PCI) requirements. Which solution will address the Security team's concerns and allow the Developers to try new services?
A) Implement a strong identity and access management model that includes users, groups, and roles in various AWS accounts. Ensure that centralized AWS CloudTrail logging is enabled to detect anomalies. Build automation with AWS Lambda to tear down unapproved AWS resources for governance.
B) Build a multi-account strategy based on business units, environments, and specific regulatory requirements. Implement SAML-based federation across all AWS accounts with an on-premises identity store. Use AWS Organizations and build organizational units (OUs) structure based on regulations and service governance. Implement service control policies across OUs.
C) Implement a multi-account strategy based on business units, environments, and specific regulatory requirements. Ensure that only PCI-compliant services are approved for use in the accounts. Build IAM policies to give access to only PCI-compliant services for governance.
D) Build one AWS account for the company for strong security controls. Ensure that all the service limits are raised to meet company scalability requirements. Implement SAML federation with an on-premises identity store, and ensure that only approved services are used in the account.
Correct Answer:

Verified
Correct Answer:
Verified
Q799: Your department creates regular analytics reports from
Q800: A user is creating a snapshot of
Q801: A user is sending a custom metric
Q802: <img src="https://d2lvgg3v3hfg70.cloudfront.net/C1091/.jpg" alt=" An organization has
Q803: A company uses Amazon S3 to store
Q805: Does Autoscaling automatically assign tags to resources?<br>A)
Q806: IAM users do not have permission to
Q807: As a part of building large applications
Q808: A company is planning to migrate an
Q809: You are designing an intrusion detection prevention