Study. uk . com
  1. Home
  2. All questions
  3. Question 21

AWS Certified Solutions Architect study material · question 21 of 500

An administrator removes the FullAWSAccess policy from an organizational unit without attaching any other allow policy. What is the result for member accounts in that OU?

  1. Only write actions fail, while reads continue
  2. Nothing changes, because FullAWSAccess is advisory
  3. The accounts revert to the permissions of the management account
  4. Every AWS action from those accounts fails
Show the answer

Answer: D. Every AWS action from those accounts fails

SCPs grant nothing, so removing the only allow policy leaves no permitted actions and every call from those accounts is refused.

Source: Service control policies (SCPs) (Amazon Web Services) — Testing effects of SCPs — Note

Challenge yourself on this topic → Study as cards