SCS-C02 Identity and Access Management • Set 16
SCS-C02 Identity and Access Management Practice Test 16 — 15 questions with explanations. Free, no signup.
A large enterprise has multiple AWS accounts managed via AWS Organizations. The security team wants to enforce that all IAM roles in all accounts must have a maximum session duration of 1 hour. They create an SCP that denies creating or updating roles if the MaxSessionDuration is greater than 3600 seconds. The SCP is attached to the root OU. After applying the SCP, the development team reports that they cannot create any new IAM roles, even with a session duration of 1 hour. They are using CloudFormation to create roles. What is the MOST likely reason for the failure?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.