SCS-C02 Management and Security Governance • Set 7
SCS-C02 Management and Security Governance Practice Test 7 — 15 questions with explanations. Free, no signup.
A company is using AWS Organizations with a management account and several member accounts. The security team has created an SCP that denies access to all actions for the 'ec2:*' service unless the request comes from a specific VPC endpoint. The SCP is attached to the organization root. However, users in a member account are still able to launch EC2 instances from the AWS Management Console, which does not use a VPC endpoint. The SCP is as follows:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": "ec2:*",
"Resource": "*",
"Condition": {
"StringNotEquals": {"aws:sourceVpce": "vpce-12345678"
}
}
}
]
}What is the most likely reason the SCP is not preventing the users from launching instances?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.