Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Amazon Exam SAP-C02 Topic 9 Question 36 Discussion

Actual exam question for Amazon's SAP-C02 exam
Question #: 36
Topic #: 9
[All SAP-C02 Questions]

A large mobile gaming company has successfully migrated all of its on-premises infrastructure to the AWS Cloud. A solutions architect is reviewing the environment to ensure that it was built according to the design and that it is running in alignment with the Well-Architected Framework.

While reviewing previous monthly costs in Cost Explorer, the solutions architect notices that the creation and subsequent termination of several large instance types account for a high proportion of the costs. The solutions architect finds out that the company's developers are launching new Amazon EC2 instances as part of their testing and that the developers are not using the appropriate instance types.

The solutions architect must implement a control mechanism to limit the instance types that only the developers can launch.

Which solution will meet these requirements?

Show Suggested Answer Hide Answer
Suggested Answer: B, E

Create AWS Organization:

In the AWS Management Console, navigate to AWS Organizations and create a new organization in the parent account.

Invite LOB Accounts:

Invite each Line of Business (LOB) account to join the organization. This allows centralized management and governance of all accounts.

Enable Consolidated Billing:

Enable consolidated billing in the billing console of the parent account. Link all LOB accounts to ensure a single consolidated invoice that breaks down costs per account.

Apply Service Control Policies (SCPs):

Implement Service Control Policies (SCPs) to define the services and features permitted for each LOB account as per the governance policy, while still delegating full administrative permissions to the LOB accounts.

By consolidating billing and using AWS Organizations, the company can achieve centralized billing and governance while maintaining independent administrative control for each LOB account


Contribute your Thoughts:

Macy
1 days ago
Whichever option we choose, I hope the developers don't start launching instances with their credit cards instead. That would be a whole new problem to deal with!
upvoted 0 times
...
Brande
2 days ago
D seems like overkill for this scenario. Creating a custom image pipeline just to control instance types? I'd go with a more straightforward approach like C or B.
upvoted 0 times
...
Tonja
7 days ago
Option B looks good too. Using a launch template to restrict the instance types is a neat way to enforce the policy, and it's more user-friendly for the developers.
upvoted 0 times
...
Tamar
9 days ago
I'm not sure, but I think option B could also work by assigning launch templates to developers' IAM accounts.
upvoted 0 times
...
Denise
10 days ago
I think option C is the best solution. By creating a custom IAM policy, we can granularly control the instance types the developers can launch, without impacting the rest of the organization.
upvoted 0 times
...
Junita
12 days ago
I agree with Kanisha, creating a managed rule in AWS Config seems like the most efficient way to limit instance types.
upvoted 0 times
...
Kanisha
27 days ago
I think option A is the best solution.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77