Multiple Choice
A company manages hundreds of AWS accounts centrally in an organization in AWS Organizations. The company recently started to allow product teams to create and manage their own S3 access points in their accounts. The S3 access points can be accessed only within VPCs, not on the Internet. What is the MOST operationally efficient way to enforce this requirement?
A) Set the S3 access point resource policy to deny the s3:CreateAccessPoint action unless the s3:AccessPointNetworkOrigin condition key evaluates to VPC.
B) Create an SCP at the root level in the organization to deny the s3:CreateAccessPoint action unless the s3:AccessPointNetworkOrigin condition key evaluates to VPC.
C) Use AWS CloudFormation StackSets to create a new IAM policy in each AWS account that allows the s3:CreateAccessPoint action only if the s3:AccessPointNetworkOrigin condition key evaluates to VPC.
D) Set the S3 bucket policy to deny the s3:CreateAccessPoint action unless the s3:AccessPointNetworkOrigin condition key evaluates to VPC.
Correct Answer:

Verified
Correct Answer:
Verified
Q304: A company wants to launch an online
Q305: A company is building an AWS landing
Q306: A user has enabled detailed CloudWatch monitoring
Q307: You are running a news website in
Q308: A user has launched a dedicated EBS
Q310: A user is configuring MySQL RDS with
Q311: A user is running a batch process
Q312: A company has several Amazon EC2 instances
Q313: In Amazon Elastic Compute Cloud, you can
Q314: An AWS partner company is building a