Study. uk . com
  1. Home
  2. All questions
  3. Question 102

AWS Certified Solutions Architect study material · question 102 of 500

An organization wants to cap what can be done to resources in member accounts without editing each resource policy. Which two statements about resource control policies are correct? Choose two.

  1. An RCP grants permissions to resources directly
  2. An RCP applies to the management account as well
  3. An RCP sets the maximum permissions for resources across member accounts
  4. An explicit deny in an RCP overrides an allow elsewhere
Show the answer

Answer: C. An RCP sets the maximum permissions for resources across member accounts
D. An explicit deny in an RCP overrides an allow elsewhere

RCPs cap resource permissions centrally and their explicit denies win, but like SCPs they grant nothing themselves.

Source: Policies and permissions in AWS Identity and Access Managem… (Amazon Web Services) — AWS Organizations resource control policies (RCPs)

Challenge yourself on this topic → Study as cards