- Home
- All questions
- Question 102
AWS Certified Solutions Architect study material · question 102 of 500
An organization wants to cap what can be done to resources in member accounts without editing each resource policy. Which two statements about resource control policies are correct? Choose two.
Show the answer
Answer: C. An RCP sets the maximum permissions for resources across member accounts
D. An explicit deny in an RCP overrides an allow elsewhere
RCPs cap resource permissions centrally and their explicit denies win, but like SCPs they grant nothing themselves.
Source: Policies and permissions in AWS Identity and Access Managem… (Amazon Web Services) — AWS Organizations resource control policies (RCPs)