Summer Special Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: vce65

A company has its accounts in an organization in AWS Organizations.

A company has its accounts in an organization in AWS Organizations. The company deploys its first service control policy (SCP) to an organizational unit (OU). The SCP denies the iam:CreateUser action. Only the newly created SCP is attached to the OU.

After deployment of the SCP, users in the OU who assume a developer IAM role can no longer launch Amazon EC2 instances.

Which action should a SysOps administrator take to resolve this issue?

A.

Add a permissions boundary to the developer IAM role to explicitly allow the ec2:RunInstances action.

B.

Update the SCP to include an additional statement that allows all actions on all resources.

C.

Update the SCP to include an additional statement that allows the ec2:RunInstances action.

D.

Update the SCP by changing the denied iam:CreateUser action to iam:Create*.

Amazon Web Services SOA-C02 Summary

  • Vendor: Amazon Web Services
  • Product: SOA-C02
  • Update on: Jul 30, 2025
  • Questions: 556
Price: $52.5  $149.99
Buy Now SOA-C02 PDF + Testing Engine Pack

Payments We Accept

Your purchase with ExamsVCE is safe and fast. Your products will be available for immediate download after your payment has been received.
The ExamsVCE website is protected by 256-bit SSL from McAfee, the leader in online security.

examsvce payment method