Study. uk . com
  1. Home
  2. All questions
  3. Question 88

AWS Certified Solutions Architect study material · question 88 of 500

Before tightening a service control policy, a team wants to know which services an account genuinely uses. Which two data sources reveal this?

  1. Service-last-accessed data in IAM and CloudTrail API logs
  2. AWS Budgets alerts and Cost Explorer forecasts
  3. Amazon Inspector findings and Macie findings
  4. VPC flow logs and Route 53 query logs
Show the answer

Answer: A. Service-last-accessed data in IAM and CloudTrail API logs

Both show real service usage, which is how an SCP is tightened without cutting off something the account depends on.

Source: Service control policies (SCPs) (Amazon Web Services) — Testing effects of SCPs

Challenge yourself on this topic → Study as cards