Multiple Choice
A financial services company is moving to AWS and wants to enable developers to experiment and innovate while preventing access to production applications. The company has the following requirements: Production workloads cannot be directly connected to the internet. All workloads must be restricted to the us-west-2 and eu-central-1 Regions. Notification should be sent when developer sandboxes exceed $500 in AWS spending monthly. Which combination of actions needs to be taken to create a multi-account structure that meets the company's requirements? (Choose three.)
A) Create accounts for each production workload within an organization in AWS Organizations. Place the production accounts within an organizational unit (OU) . For each account, delete the default VPC. Create an SCP with a Deny rule for the attach an internet gateway and create a default VPC actions. Attach the SCP to the OU for the production accounts.
B) Create accounts for each production workload within an organization in AWS Organizations. Place the production accounts within an organizational unit (OU) . Create an SCP with a Deny rule on the attach an internet gateway action. Create an SCP with a Deny rule to prevent use of the default VPC. Attach the SCPs to the OU for the production accounts.
C) Create a SCP containing a Deny Effect for cloudfront:*, iam:*, route53:*, and support:* with a StringNotEquals condition on an aws:RequestedRegion condition key with us-west-2 and eu-central-1 values. Attach the SCP to the organization's root.
D) Create an IAM permission boundary containing a Deny Effect for cloudfront:*, iam:*, route53:*, and support:* with a StringNotEquals condition on an aws:RequestedRegion condition key with us-west-2 and eu-central-1 values. Attach the permission boundary to an IAM group containing the development and production users.
E) Create accounts for each development workload within an organization in AWS Organizations. Place the development accounts within an organizational unit (OU) . Create a custom AWS Config rule to deactivate all IAM users when an account's monthly bill exceeds $500.
F) Create accounts for each development workload within an organization in AWS Organizations. Place the development accounts within an organizational unit (OU) . Create a budget within AWS Budgets for each development account to monitor and report on monthly spending exceeding $500.
Correct Answer:

Verified
Correct Answer:
Verified
Q119: By default, Amazon Cognito maintains the last-written
Q120: A solutions architect needs to advise a
Q121: A company has a large on-premises Apache
Q122: A company's application is increasingly popular and
Q123: Can Provisioned IOPS be used on RDS
Q125: A company has an application that runs
Q126: You control access to S3 buckets and
Q127: How can an EBS volume that is
Q128: In DynamoDB, to get a detailed listing
Q129: You've been hired to enhance the overall