Soru

Zorluk: KolayMulti-Account Management and Governance

A company is setting up a new multi-account AWS environment using AWS Organizations. The company wants to implement centralized user authentication that integrates with their existing corporate identity provider. Additionally, they need to enforce a security policy that prevents any administrator in the member accounts from deleting Amazon S3 buckets that store access logs.

Which combination of AWS services or features will meet these requirements? (Select TWO.)

  1. AWS IAM Identity Center federated with the corporate identity provider for centralized user accessCevap
  2. Service Control Policies (SCPs) in AWS Organizations to deny the deletion of the log buckets across member accountsCevap
  3. C
    Individual IAM users created in each member account with configured federation settings for each employee
  4. D
    An IAM policy attached to the root user of each member account that restricts access to the log buckets
  5. E
    The AWS account root user credentials of the management account used to perform daily log auditing tasks

Cevap

Configure AWS IAM Identity Center federated with the corporate identity provider for centralized user access, and apply Service Control Policies (SCPs) in AWS Organizations to deny the deletion of the log buckets across member accounts.
Centralized user access across multiple AWS accounts should be implemented using AWS IAM Identity Center federated with the external identity provider. To enforce administrative compliance and prevent critical resource deletion (such as S3 access log buckets) across member accounts, Service Control Policies (SCPs) must be attached to the appropriate Organizational Units (OUs) or accounts in AWS Organizations.

Adım Adım Çözüm

1
Identify the requirement for centralized identity management and federation.
Determine that AWS IAM Identity Center is the standard service for federating an external identity provider with multiple AWS accounts.
This centralizes authentication control and avoids the need to manage individual credentials in each account.
2
Identify the requirement to restrict actions (bucket deletion) across all member accounts, including for administrators.
Determine that Service Control Policies (SCPs) in AWS Organizations can enforce maximum permission limits (guardrails) across accounts.
SCPs apply to all users and roles in the member accounts, including the root user, ensuring administrative compliance.

Anahtar Kavram

Centralized multi-account governance is achieved by combining federated access management via AWS IAM Identity Center with Organization-level guardrails using Service Control Policies (SCPs).
Bu soruyu puanla