AWS Certified Security – Specialty (SCS-C02) — Question 255

A security administrator is restricting the capabilities of company root user accounts. The company uses AWS Organizations and has all features enabled.
The management account is used for billing and administrative purposes, but it is not used for operational AWS resource purposes.

How can the security administrator restrict usage of member root user accounts across the organization?

Answer options

Correct answer: C

Explanation

The correct answer, C, involves creating an Organizational Unit (OU) with an SCP that can effectively manage root user account usage across the organization. Options A and B do not provide a comprehensive organizational approach to restrict root account usage, and option D focuses on monitoring rather than restricting access.