- Home
- All questions
- Question 88
AWS Certified Solutions Architect study material · question 88 of 500
Before tightening a service control policy, a team wants to know which services an account genuinely uses. Which two data sources reveal this?
Show the answer
Answer: A. Service-last-accessed data in IAM and CloudTrail API logs
Both show real service usage, which is how an SCP is tightened without cutting off something the account depends on.
Source: Service control policies (SCPs) (Amazon Web Services) — Testing effects of SCPs